HIGH · 8.4

CVE-2016-3134

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via...

Vulnerability Description

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

CVSS Score

8.4

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NovellSuse Linux Enterprise Software Development Kit11.0
NovellSuse Linux Enterprise Debuginfo11.0
NovellSuse Linux Enterprise Desktop12.0
NovellSuse Linux Enterprise Live Patching12.0
NovellSuse Linux Enterprise Module For Public Cloud12.0
NovellSuse Linux Enterprise Real Time Extension12.0
NovellSuse Linux Enterprise Server11.0
NovellSuse Linux Enterprise Workstation Extension12.0
LinuxLinux Kernel<= 4.5.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-3134?

CVE-2016-3134 is a vulnerability with a CVSS score of 8.4 (HIGH). The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via...

How severe is CVE-2016-3134?

CVE-2016-3134 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-3134?

Check the references section above for vendor advisories and patch information. Affected products include: Novell Suse Linux Enterprise Software Development Kit, Novell Suse Linux Enterprise Debuginfo, Novell Suse Linux Enterprise Desktop, Novell Suse Linux Enterprise Live Patching, Novell Suse Linux Enterprise Module For Public Cloud.