CVE-2016-7425

NameCVE-2016-7425
DescriptionThe arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-670-1, DSA-3696-1
NVD severityhigh (attack range: local)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)wheezy3.2.78-1vulnerable
wheezy (security)3.2.96-2fixed
jessie3.16.51-2fixed
jessie (security)3.16.43-2+deb8u5fixed
stretch4.9.65-3fixed
stretch (security)4.9.30-2+deb9u5fixed
buster4.13.13-1fixed
sid4.14.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsource(unstable)4.7.8-1high
linuxsourcejessie3.16.36-1+deb8u2highDSA-3696-1
linuxsourcewheezy3.2.82-1highDLA-670-1

Notes

http://marc.info/?l=linux-scsi&m=147394713328707&w=2
Upstream commit: https://git.kernel.org/linus/7bc2b55a5c030685b399bb65b6baa9ccc3d1f167

Search for package or bug name: Reporting problems