HIGH · 7.8

CVE-2016-3672

The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the inte...

Vulnerability Description

The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption resource limits.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CanonicalUbuntu Linux12.04
NovellSuse Linux Enterprise Software Development Kit12.0
NovellSuse Linux Enterprise Desktop12.0
NovellSuse Linux Enterprise Live Patching12.0
NovellSuse Linux Enterprise Module For Public Cloud12.0
NovellSuse Linux Enterprise Real Time Extension12.0
NovellSuse Linux Enterprise Server12.0
NovellSuse Linux Enterprise Workstation Extension12.0
LinuxLinux Kernel<= 4.5.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-3672?

CVE-2016-3672 is a vulnerability with a CVSS score of 7.8 (HIGH). The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the inte...

How severe is CVE-2016-3672?

CVE-2016-3672 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-3672?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Novell Suse Linux Enterprise Software Development Kit, Novell Suse Linux Enterprise Desktop, Novell Suse Linux Enterprise Live Patching, Novell Suse Linux Enterprise Module For Public Cloud.