PatchSiren

Linux CVE debriefs · Page 122

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2017-02-08

CVE-2017-0435

CVE-2017-0435 is a high-severity elevation-of-privilege issue in the Qualcomm sound driver on Android. According to the CVE record, a local malicious application could potentially execute code in kernel context, but the issue is described as requiring prior compromise of a privileged process.

HIGH Linux CVE published 2017-02-08

CVE-2017-0432

CVE-2017-0432 is a high-severity elevation of privilege issue affecting an Android MediaTek driver in Kernel-3.10. The CVE description says a local malicious application could execute arbitrary code in kernel context, but exploitation first requires compromising a privileged process. In practice, that means the issue is most concerning on devices where an attacker already has some on-device foothold or ca [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2017-0430

CVE-2017-0430 is a local elevation-of-privilege issue in Broadcom Wi‑Fi driver code used by affected Android builds. A malicious local app could execute code in kernel context, and Android’s advisory states the bug may lead to permanent device compromise that could require reflashing to recover.

HIGH Linux CVE published 2017-02-08

CVE-2017-0427

CVE-2017-0427 describes a local elevation of privilege flaw in the kernel file system path that could let a malicious app execute code in kernel context. The affected scope in the supplied record includes Android up to 7.1.1 and Linux kernel 3.10 and 3.18. The Android bulletin text characterizes the impact as Critical because successful abuse could lead to permanent device compromise and, in some cases, r [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2016-8481

CVE-2016-8481 is a High-severity elevation-of-privilege flaw in the Qualcomm sound driver path used by Android/Linux kernel builds. The supplied description says a local malicious app could execute arbitrary code in kernel context, and that the issue is rated High because it first requires compromising a privileged process. NVD classifies the issue as CVSS 7.0 with local attack characteristics and user in [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2016-8480

CVE-2016-8480 is a high-severity elevation-of-privilege issue affecting Android systems and the Linux kernel branches listed by NVD. The CVE description says a local malicious application could execute arbitrary code in kernel context, but only after first compromising a privileged process. NVD also ties the issue to Android devices up to 7.1.1 and Linux kernel 3.10 and 3.18, with a CVSS 3.0 vector of AV: [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2016-8476

CVE-2016-8476 describes a High-severity elevation of privilege flaw in a Qualcomm Wi‑Fi driver. Per the published description, a local malicious application could execute arbitrary code in kernel context, and the issue was rated High because it first requires compromising a privileged process. NVD associates the issue with Android and Linux kernel 3.10/3.18, with Android versions up to 7.1.1 listed as vul [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2016-8421

CVE-2016-8421 is a high-severity elevation-of-privilege issue affecting Android systems that use the Qualcomm Wi‑Fi driver. NVD and the Android security bulletin describe impact on Android kernel 3.10 and 3.18, with the potential for kernel-context code execution from a local attack path.

HIGH Linux CVE published 2017-02-08

CVE-2016-8420

CVE-2016-8420 is a high-severity elevation-of-privilege flaw in Qualcomm Wi‑Fi driver code that can let a local malicious app execute arbitrary code in kernel context. NVD lists affected Android builds up to 7.1.1 and Linux kernels 3.10 and 3.18, and the Android vendor bulletin is the primary patch reference in the supplied corpus.

HIGH Linux CVE published 2017-02-08

CVE-2016-8419

CVE-2016-8419 is a high-severity elevation-of-privilege issue affecting Android systems with the Qualcomm Wi‑Fi driver. According to the CVE description and Android security bulletin reference, a local malicious application could execute arbitrary code in the kernel context, but the issue is not a simple one-step local bug: the rating notes that exploitation first requires compromising a privileged proces [truncated]

MEDIUM Linux CVE published 2017-02-08

CVE-2016-8414

CVE-2016-8414 is an information disclosure vulnerability in Qualcomm Secure Execution Environment Communicator. NVD rates it as medium severity because exploitation is local and first requires compromising a privileged process; successful abuse could let a malicious app access data beyond its permission level.

HIGH Linux CVE published 2017-02-07

CVE-2016-10044

CVE-2016-10044 is a Linux kernel local privilege-escalation issue in the aio_mount path. According to NVD and the referenced kernel patch, the flaw allowed execute access to be handled too loosely, which could let a local user bypass intended SELinux W^X policy restrictions and potentially gain privileges via io_setup. The issue is high impact because it affects confidentiality, integrity, and availabilit [truncated]

HIGH Linux CVE published 2017-02-07

CVE-2014-9914

CVE-2014-9914 is a Linux kernel race condition in ip4_datagram_release_cb that can trigger a use-after-free during multithreaded access to internal IPv4 UDP socket data structures. NVD rates the issue High and maps it to local privilege escalation or denial of service on affected Linux kernel releases, with Android devices also listed in the vulnerable CPE range through 7.1.1.

MEDIUM Linux CVE published 2017-02-06

CVE-2017-5577

CVE-2017-5577 is a Linux kernel vulnerability in the VideoCore DRM (vc4) driver that can let a local attacker cause a denial of service. The issue is tied to error handling in vc4_get_bcl(): when certain overflow conditions are detected, the function does not set errno as expected, which can lead to an incorrect pointer dereference and kernel OOPS during a VC4_SUBMIT_CL ioctl path. The NVD record rates th [truncated]

HIGH Linux CVE published 2017-02-06

CVE-2017-5576

CVE-2017-5576 is a Linux kernel flaw in the VideoCore DRM driver that was published on 2017-02-06. A crafted VC4_SUBMIT_CL ioctl size value can trigger an integer overflow in vc4_get_bcl, creating a local denial-of-service risk and possibly other unspecified impact on affected systems.

MEDIUM Linux CVE published 2017-02-06

CVE-2017-5551

CVE-2017-5551 is a Linux kernel local privilege issue affecting systems running kernel versions before 4.9.6. The flaw is in simple_set_acl in fs/posix_acl.c and can preserve the setgid bit during a setxattr call on tmpfs. In practical terms, a local user may be able to gain group privileges when a restrictive setgid program is present. The record notes this is an incomplete fix for CVE-2016-7097.

MEDIUM Linux CVE published 2017-02-06

CVE-2017-5550

CVE-2017-5550 is a Linux kernel information-disclosure issue in pipe_advance that can expose uninitialized heap memory to a local user in limited, opportunistic circumstances. NVD lists affected kernels through 4.9.4 and notes the issue is fixed in Linux 4.9.5. The impact is confidentiality-only and requires local access, so the main concern is unintended data exposure on multi-user systems.

MEDIUM Linux CVE published 2017-02-06

CVE-2017-5549

CVE-2017-5549 is a local information-disclosure issue in the Linux kernel’s USB serial kl5kusb105 driver. When line-status reads fail, the affected function can place uninitialized heap-memory contents into a log entry, which may let a local user recover sensitive data by reading kernel logs. The vulnerable range is listed as Linux kernel 4.9.4 and earlier, with the fix associated with Linux 4.9.5.

HIGH Linux CVE published 2017-02-06

CVE-2017-5548

CVE-2017-5548 is a Linux kernel vulnerability in drivers/net/ieee802154/atusb.c affecting 4.9.x before 4.9.6. According to the NVD record, the issue involves incorrect interaction with CONFIG_VMAP_STACK and a DMA scatterlist that spans more than one virtual page. A local user can trigger denial of service, memory corruption, and possibly other unspecified impact.

HIGH Linux CVE published 2017-02-06

CVE-2017-5547

CVE-2017-5547 is a Linux kernel vulnerability in drivers/hid/hid-corsair.c that can let a local user trigger a denial of service, including system crash or memory corruption, and may have other unspecified impact. The issue is tied to incorrect interaction with CONFIG_VMAP_STACK and DMA scatterlists that span more than one virtual page. NVD rates the issue HIGH and identifies affected Linux kernel release [truncated]

HIGH Linux CVE published 2017-02-06

CVE-2017-5546

CVE-2017-5546 is a Linux kernel flaw in the slab allocator’s freelist-randomization logic. NVD describes it as allowing a local user to trigger duplicate freelist entries and a system crash, with the possibility of other unspecified impact in some circumstances. The issue is fixed in Linux 4.9.5, and NVD rates it High severity with a local, low-privilege attack path.

MEDIUM Linux CVE published 2017-02-06

CVE-2017-2596

CVE-2017-2596 affects the Linux kernel's KVM VMX nested virtualization code and can be triggered by a local guest user on affected systems. According to the NVD record, the issue stems from improper emulation of the VMXON instruction in nested_vmx_check_vmptr, which can lead to mishandling of page references and host memory consumption, resulting in denial of service. The vulnerable range recorded in the [truncated]

HIGH Linux CVE published 2017-02-06

CVE-2017-2583

CVE-2017-2583 affects the Linux kernel’s KVM x86 emulation path. The flaw is in how `load_segment_descriptor` in `arch/x86/kvm/emulate.c` handles a `MOV SS, NULL selector` instruction. According to the CVE record, a crafted application in a guest can trigger a denial of service (guest OS crash) and may also gain guest OS privileges. The vulnerability is documented as fixed in Linux kernel 4.9.5 and earlie [truncated]

MEDIUM Linux CVE published 2017-02-06

CVE-2016-10208

CVE-2016-10208 is a Linux kernel ext4 vulnerability in ext4_fill_super that can lead to a denial of service through an out-of-bounds read and crash when a crafted ext4 image is processed. NVD maps the issue to Linux kernel versions through 4.9.8 and assigns CVSS 4.3 (MEDIUM) with a physical-access attack vector. The main risk is kernel instability on systems that may mount untrusted or attacker-supplied e [truncated]

MEDIUM Linux CVE published 2017-02-06

CVE-2016-10154

CVE-2016-10154 affects Linux kernel 4.9.x before 4.9.1. When CONFIG_VMAP_STACK is enabled, the smbhash function in fs/cifs/smbencrypt.c can interact incorrectly with scatterlists that span more than one virtual page. NVD describes the result as a local denial of service through system crash or memory corruption, with possible unspecified additional impact.

HIGH Linux CVE published 2017-02-06

CVE-2016-10153

CVE-2016-10153 is a Linux kernel issue affecting 4.9.x before 4.9.6 when CONFIG_VMAP_STACK is enabled. According to the NVD description, the crypto scatterlist API interacts incorrectly with this stack configuration, with impact ranging from system crash or memory corruption to possibly other unspecified effects. The problem is tied to earlier net/ceph/crypto.c code paths and is exploitable by local users [truncated]

CRITICAL Linux CVE published 2017-02-06

CVE-2016-10150

CVE-2016-10150 is a critical use-after-free vulnerability in the Linux kernel's KVM device creation path, specifically kvm_ioctl_create_device in virt/kvm/kvm_main.c. On affected kernel versions before 4.8.13, a crafted ioctl request against /dev/kvm can cause a host denial of service and may also allow privilege escalation. Systems that run KVM on Linux hosts should treat this as urgent remediation work.

MEDIUM Linux CVE published 2017-02-06

CVE-2010-5328

CVE-2010-5328 is a Linux kernel denial-of-service issue in which signals with a process group ID of zero can reach the swapper process. According to the CVE description and NVD, this can let a local user crash the system on affected kernels before 2.6.35. NVD rates the issue as local, low-complexity, low-privilege, and availability-impacting only, which fits a kernel stability problem rather than a data-e [truncated]

MEDIUM Linux CVE published 2017-01-18

CVE-2016-10147

CVE-2016-10147 is a local denial-of-service issue in the Linux kernel’s crypto/mcryptd.c path. According to the CVE record, a local user can trigger a NULL pointer dereference and crash the system by using an AF_ALG socket with an incompatible algorithm, with mcryptd(md5) given as an example. The NVD record maps affected Linux kernel versions to those before 4.8.15 and assigns a medium severity score (CVS [truncated]

HIGH Linux CVE published 2017-01-15

CVE-2017-2584

CVE-2017-2584 is a Linux kernel vulnerability in the x86 KVM instruction emulation path. According to the CVE description and NVD record, a crafted local application can trigger a use-after-free in arch/x86/kvm/emulate.c during emulation of fxrstor, fxsave, sgdt, and sidt, which may lead to sensitive kernel memory disclosure or a denial of service. The affected range listed by NVD includes Linux kernel ve [truncated]