10

CVE-2016-7117

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DebianDebian Linux Version7.0
LinuxLinux Kernel Version >= 2.6.33 < 3.2.80
LinuxLinux Kernel Version >= 3.3 < 3.4.113
LinuxLinux Kernel Version >= 3.5 < 3.10.102
LinuxLinux Kernel Version >= 3.11 < 3.12.59
LinuxLinux Kernel Version >= 3.13 < 3.14.67
LinuxLinux Kernel Version >= 3.15 < 3.16.35
LinuxLinux Kernel Version >= 3.17 < 3.18.37
LinuxLinux Kernel Version >= 3.19 < 4.1.28
LinuxLinux Kernel Version >= 4.2.0 < 4.4.8
LinuxLinux Kernel Version >= 4.5.0 < 4.5.2
CanonicalUbuntu Linux Version16.04 SwEditionlts
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.56% 0.932
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/93304
Third Party Advisory
VDB Entry
https://bugzilla.novell.com/show_bug.cgi?id=1003077
Third Party Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1382268
Third Party Advisory
Issue Tracking