SB2016050932 - Permissions, Privileges, and Access Controls in linux-vanilla (Alpine package) 



SB2016050932 - Permissions, Privileges, and Access Controls in linux-vanilla (Alpine package)

Published: May 9, 2016

Security Bulletin ID SB2016050932
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2016-3157)

The vulnerability allows a local authenticated user to execute arbitrary code.

The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain sensitive information by leveraging I/O port access.


Remediation

Install update from vendor's website.