Vulnerability Description
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell | Suse Linux Enterprise Desktop | 12.0 |
| Novell | Suse Linux Enterprise Workstation Extension | 12.0 |
| Novell | Suse Linux Enterprise Module For Public Cloud | 12.0 |
| Novell | Suse Linux Enterprise Server | 11.0 |
| Novell | Opensuse Leap | 42.1 |
| Novell | Suse Linux Enterprise Software Development Kit | 11.0 |
| Redhat | Enterprise Linux | 6.0 |
| Canonical | Ubuntu Linux | 12.04 |
| Linux | Linux Kernel | >= 2.6.30, < 3.2.80 |
| Oracle | Linux | 6 |
| Novell | Suse Linux Enterprise Real Time Extension | 11.0 |
| Novell | Suse Linux Enterprise Live Patching | 12.0 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1f461dPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.htmlMailing ListRelease NotesThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.htmlMailing ListRelease NotesThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlMailing ListRelease NotesThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlMailing ListThird Party Advisory
- http://www.debian.org/security/2016/dsa-3607Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.5.2Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2016/05/15/2Mailing ListPatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.hThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmThird Party Advisory
- http://www.securityfocus.com/bid/90605Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036763Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-4805?
CVE-2016-4805 is a vulnerability with a CVSS score of 7.8 (HIGH). Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or poss...
How severe is CVE-2016-4805?
CVE-2016-4805 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4805?
Check the references section above for vendor advisories and patch information. Affected products include: Novell Suse Linux Enterprise Desktop, Novell Suse Linux Enterprise Workstation Extension, Novell Suse Linux Enterprise Module For Public Cloud, Novell Suse Linux Enterprise Server, Novell Opensuse Leap.