OpenSource For You

Linux kernel gets fix for serious DoS vulnerabil­ity

-

The Linux community has received a patch for a security hole that could cause a denial of service (DoS) attack. Linux distributi­ons that are affected by the flaw include the recent versions of Debian, Fedora, Red Hat Enterprise Linux and Ubuntu.

Security researcher

Philip Pettersson spotted the vulnerabil­ity, designated CVE2016-8655, within the packet_ set_ring function of the Linux kernel. Pettersson described a race condition that exploits a local user through AF_PACKET sockets with CAP_NET_RAW in the network namespace.

“A local unprivileg­ed attacker could use this to cause a denial of service (system crash) or run arbitrary code with administra­tive privileges,” read the brief descriptio­n.

Apart from the DoS vulnerabil­ity spotted by Pettersson, researcher­s have found CVE-2016-6480 and CVE-2016-6828. Both the flaws exist within the kernel code and can crash the system by a local attacker.

Patches for all the three vulnerabil­ities have started rolling out for major Linux distributi­ons. It is recommende­d that users download the latest versions to avoid any severe attacks.

 ??  ??

Newspapers in English

Newspapers from India