Overview
About vulnerability
A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.Details
- Affected product:
- CentOS 6 ELS , CentOS 7 ELS , CloudLinux 6 ELS , Oracle Linux 6 ELS , Ubuntu 16.04 ELS
- Affected packages:
- kernel @ 2.6.32 (+4 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Oracle Linux 6 UEK 4 | Released |
85 kernels
|
| Oracle Linux 7 UEK 4 | Released |
120 kernels
|
| Ubuntu 16.04 AWS ESM | Will Not Fix | — |