CVE-2016-4558
Bug #1579140 reported by
Steve Beattie
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Fix Released
|
Medium
|
Unassigned | ||
Yakkety |
Fix Released
|
Medium
|
Unassigned | ||
linux-armadaxp (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-flo (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
New
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-goldfish (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
New
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-lts-quantal (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-raring (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-saucy (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-trusty (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-utopic (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-vivid (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-wily (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-lts-xenial (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Fix Released
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-mako (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
New
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-manta (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned | ||
linux-raspi2 (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Fix Released
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-snapdragon (Ubuntu) |
New
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
New
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Fix Released
|
Medium
|
Unassigned | ||
Yakkety |
New
|
Medium
|
Unassigned | ||
linux-ti-omap4 (Ubuntu) |
Invalid
|
Medium
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Unassigned | ||
Trusty |
Invalid
|
Medium
|
Unassigned | ||
Vivid |
Won't Fix
|
Undecided
|
Unassigned | ||
Wily |
Invalid
|
Medium
|
Unassigned | ||
Xenial |
Invalid
|
Medium
|
Unassigned | ||
Yakkety |
Invalid
|
Medium
|
Unassigned |
Bug Description
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count.
Break-Fix: 1be7f75d1668d62
Changed in linux-lts-quantal (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-lts-quantal (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-ti-omap4 (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-ti-omap4 (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-ti-omap4 (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-ti-omap4 (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-ti-omap4 (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-lts-raring (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-raring (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-lts-raring (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-lts-raring (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-lts-raring (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-armadaxp (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-armadaxp (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-armadaxp (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-armadaxp (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-armadaxp (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-lts-saucy (Ubuntu Precise): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-saucy (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-lts-saucy (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-lts-saucy (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-lts-saucy (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-manta (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-lts-vivid (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-raspi2 (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-snapdragon (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-mako (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-lts-utopic (Ubuntu Trusty): | |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-goldfish (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Precise): | |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Wily): | |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Yakkety): | |
importance: | Undecided → Medium |
Changed in linux-flo (Ubuntu Trusty): | |
status: | New → Invalid |
importance: | Undecided → Medium |
Changed in linux-lts-xenial (Ubuntu Trusty): | |
status: | Invalid → Fix Committed |
Changed in linux-lts-xenial (Ubuntu Trusty): | |
status: | Fix Committed → New |
Changed in linux (Ubuntu Xenial): | |
status: | New → Fix Committed |
Changed in linux-lts-xenial (Ubuntu Trusty): | |
status: | New → Fix Committed |
Changed in linux-raspi2 (Ubuntu Xenial): | |
status: | New → Fix Committed |
Changed in linux-raspi2 (Ubuntu Yakkety): | |
status: | Fix Released → New |
Changed in linux-snapdragon (Ubuntu Yakkety): | |
status: | Fix Released → New |
description: | updated |
Changed in linux-armadaxp (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-flo (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-lts-saucy (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-lts-trusty (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-lts-utopic (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-lts-vivid (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-mako (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-raspi2 (Ubuntu Vivid): | |
status: | New → Won't Fix |
Changed in linux-ti-omap4 (Ubuntu Vivid): | |
status: | New → Won't Fix |
To post a comment you must log in.
CVE-2016-4558