Description
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-922-1 | linux security update |
EUVD |
EUVD-2016-1385 | Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c. |
Ubuntu USN |
USN-3422-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3422-2 | Linux kernel (Trusty HWE) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-06T03:14:42.877Z
Reserved: 2017-02-04T00:00:00.000Z
Link: CVE-2016-10200
No data.
Status : Modified
Published: 2017-03-07T21:59:00.153
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-10200
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN