Medium
Ubuntu
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel did not properly initialize the Code Segment (CS) in certain error cases. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the setsockopt() system call when handling the SO_SNDBUFFORCE andSO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability could use this to cause a denial of service (system crash or memory corruption). (CVE-2016-9793)
Baozeng Ding discovered a race condition that could lead to a use-after-free in the Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel. A local attacker could use this to cause a denial of service(system crash). (CVE-2016-9794)
Severity is medium unless otherwise noted.
Cloud Foundry BOSH stemcells are vulnerable, including:
* 3151.x versions prior to 3151.7
OSS users are strongly encouraged to follow one of the mitigations below:
Dmitry Vyukov, Andrey Konovalov, Baozeng Ding
2017-01-11: Initial vulnerability report published