Vulnerability Description
drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.8.6 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=667121Issue TrackingPatchVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.7Release Notes
- http://www.openwall.com/lists/oss-security/2016/11/06/1Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/94149
- https://access.redhat.com/errata/RHSA-2018:0676
- https://access.redhat.com/errata/RHSA-2018:1062
- https://access.redhat.com/errata/RHSA-2019:1170
- https://access.redhat.com/errata/RHSA-2019:1190
- https://bugzilla.redhat.com/show_bug.cgi?id=1391490Issue Tracking
- https://eyalitkin.wordpress.com/2016/11/06/cve-publication-cve-2016-8633/Third Party Advisory
- https://github.com/torvalds/linux/commit/667121ace9dbafb368618dbabcf07901c962ddaIssue TrackingPatchThird Party Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=667121Issue TrackingPatchVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.7Release Notes
- http://www.openwall.com/lists/oss-security/2016/11/06/1Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/94149
FAQ
What is CVE-2016-8633?
CVE-2016-8633 is a vulnerability with a CVSS score of 6.8 (MEDIUM). drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.
How severe is CVE-2016-8633?
CVE-2016-8633 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8633?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.