Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Arch Linux 2016-12-14 High: Linux-Zen Denial Of Service CVE-2016-9919

Archlinux Large Esm H500
The package linux-zen before version 4.8.13-1 is vulnerable to denial of service.
Arch Linux Security Advisory ASA-201612-14
=========================================
Severity: High
Date    : 2016-12-12
CVE-ID  : CVE-2016-9919
Package : linux-zen
Type    : denial of service
Remote  : Yes
Link    : https://wiki.archlinux.org/title/CVE

Summary
======
The package linux-zen before version 4.8.13-1 is vulnerable to denial
of service.

Resolution
=========
Upgrade to 4.8.13-1.

# pacman -Syu "linux-zen>=4.8.13-1"

The problem has been fixed upstream in version 4.8.13.

Workaround
=========
None.

Description
==========
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through
4.8.12 omits a certain check of the dst data structure, which allows
remote attackers to cause a denial of service (panic) via a fragmented
IPv6 packet.

Impact
=====
A remote attacker can cause a kernel panic by sending a fragmented IPv6
packet.

References
=========
https://bugzilla.kernel.org/show_bug.cgi?id=189851
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/
https://access.redhat.com/security/cve/CVE-2016-9919

Related News

Your message here