Vulnerability Description
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | <= 7.0 | |
| Oracle | Vm Server | 3.3 |
| Linux | Linux Kernel | <= 4.6.6 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=75ff39Issue TrackingPatch
- http://rhn.redhat.com/errata/RHSA-2016-1631.html
- http://rhn.redhat.com/errata/RHSA-2016-1632.html
- http://rhn.redhat.com/errata/RHSA-2016-1633.html
- http://rhn.redhat.com/errata/RHSA-2016-1657.html
- http://rhn.redhat.com/errata/RHSA-2016-1664.html
- http://rhn.redhat.com/errata/RHSA-2016-1814.html
- http://rhn.redhat.com/errata/RHSA-2016-1815.html
- http://rhn.redhat.com/errata/RHSA-2016-1939.html
- http://source.android.com/security/bulletin/2016-10-01.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/07/12/2Mailing ListThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.hThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmVendor Advisory
- http://www.prnewswire.com/news-releases/mitnick-attack-reappears-at-geekpwn-macaTechnical Description
- http://www.securityfocus.com/bid/91704
FAQ
What is CVE-2016-5696?
CVE-2016-5696 is a vulnerability with a CVSS score of 4.8 (MEDIUM). net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-win...
How severe is CVE-2016-5696?
CVE-2016-5696 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5696?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Oracle Vm Server, Linux Linux Kernel.