The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary.
2016-07-03T21:59:17.167
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:P/I:N/A:C
3.9
7.8
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | ≤ 4.5.5 | Yes |
Operating System | oracle | linux | 7 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.10 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |