CVE-2016-8655
CVE-2016-8655
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
Affected products
n/a · n/apublic PoCs found — 11
githubgithub.com/martinmullins/CVE-2016-8655_Android★ 12githubgithub.com/LakshmiDesai/CVE-2016-8655★ 5githubgithub.com/agkunkle/chocobo★ 0githubgithub.com/scarvell/cve-2016-8655★ 0githubgithub.com/KosukeShimofuji/CVE-2016-8655★ 0cve_referencepacketstormsecurity.com/files/140063/Linux-Kernel-4.4.0-AF_PACKET-Race-Condition-Privilege-Escalation.htmlunverifiedexploitdbwww.exploit-db.com/exploits/47170unverifiedcve_referencewww.exploit-db.com/exploits/40871/unverifiedcve_referencewww.exploit-db.com/exploits/44696/unverifiedexploitdbwww.exploit-db.com/exploits/44696unverifiedexploitdbwww.exploit-db.com/exploits/40871unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=84ac7260236a49c79eede91617700174c2c19b0chttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.htmlhttp://packetstormsecurity.com/files/140063/Linux-Kernel-4.4.0-AF_PACKET-Race-Condition-Privilege-Escalation.html