ISOMAN

CVE

CVE-2016-2117

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f43bfaeddc79effbf3d0fcb53ca477cca66f3db8
  2. http://rhn.redhat.com/errata/RHSA-2016-2574.html
  3. http://rhn.redhat.com/errata/RHSA-2016-2584.html
  4. http://www.debian.org/security/2016/dsa-3607
  5. http://www.openwall.com/lists/oss-security/2016/03/16/7
  6. http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
  7. http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
  8. http://www.securityfocus.com/bid/84500
  9. http://www.ubuntu.com/usn/USN-2989-1
  10. http://www.ubuntu.com/usn/USN-2998-1
  11. http://www.ubuntu.com/usn/USN-3000-1
  12. http://www.ubuntu.com/usn/USN-3001-1
  13. http://www.ubuntu.com/usn/USN-3002-1
  14. http://www.ubuntu.com/usn/USN-3003-1
  15. http://www.ubuntu.com/usn/USN-3004-1
  16. http://www.ubuntu.com/usn/USN-3005-1
  17. http://www.ubuntu.com/usn/USN-3006-1
  18. http://www.ubuntu.com/usn/USN-3007-1
  19. https://bugzilla.redhat.com/show_bug.cgi?id=1312298
  20. https://github.com/torvalds/linux/commit/f43bfaeddc79effbf3d0fcb53ca477cca66f3db8