SB2016042013 - Fedora 23 update for kernel



SB2016042013 - Fedora 23 update for kernel

Published: April 20, 2016 Updated: April 24, 2025

Security Bulletin ID SB2016042013
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2016-3961)

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.


2) Out-of-bounds read (CVE-ID: CVE-2016-3955)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds read error within the usbip_recv_xbuff() function in drivers/usb/usbip/usbip_common.c. A remote non-authenticated attacker can execute arbitrary code.


Remediation

Install update from vendor's website.