SB2016101702 - Denial of service in Linux kernel
Published: October 17, 2016 Updated: January 11, 2017
Security Bulletin ID
SB2016101702
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Denial of service (CVE-ID: CVE-2016-6327)
The vulnerability allows a local user to cause DoS conditions on the target system.The weakness is caused by drivers/infiniband/ulp/srpt/ib_srpt.c. By using an ABORT_TASK command attackers can abort a device write operation that leads to NULL pointer dereference and system crash.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
Remediation
Install update from vendor's website.