[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2016-726 ---- kernel perf

ID: oval:org.secpod.oval:def:1600433Date: (C)2016-08-09   (M)2023-12-20
Class: PATCHFamily: unix




It was found that nfsd is missing permissions check when setting ACL on files, this may allow a local users to gain access to any file by setting a crafted ACL. A flaw was found in the Linux kernel"s keyring handling code, where in key_reject_and_link an uninitialised variable would eventually lead to arbitrary free address which could allow attacker to use a use-after-free style attack. A leak of information was possible when issuing a netlink command of the stack memory area leading up to this function call. An attacker could use this to determine stack information for use in a later exploit. A vulnerability was found in the Linux kernel in function rds_inc_info_copy of file net/rds/recv.c. The last field "flags" of object "minfo" is not initialized. This can leak data previously at the flags location to userspace

Platform:
Amazon Linux AMI
Product:
kernel
perf
Reference:
ALAS-2016-726
CVE-2016-5696
CVE-2016-5244
CVE-2016-5243
CVE-2016-4470
CVE-2016-1237
CVE    5
CVE-2016-5696
CVE-2016-1237
CVE-2016-4470
CVE-2016-5244
...
CPE    5
cpe:/o:amazon:linux
cpe:/o:linux:linux_kernel:4.6.6
cpe:/o:linux:linux_kernel
cpe:/a:perf:perf
...

© SecPod Technologies