Wind River Support Network

HomeDefectsLIN8-2545
Fixed

LIN8-2545 : Security Advisory - linux - CVE-2016-0728

Created: Jan 20, 2016    Updated: Dec 3, 2018
Resolved Date: Jan 27, 2016
Found In Version: 8.0
Fix Version: 8.0.0.2
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Kernel

Description

http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728 says:

Perception Point Research team has identified a 0-day local privilege escalation vulnerability in the Linux kernel. While the vulnerability has existed since 2012, our team discovered the vulnerability only recently, disclosed the details to the Kernel security team, and later developed a proof-of-concept exploit. As of the date of disclosure, this vulnerability has implications for approximately tens of millions of Linux PCs and servers, and 66 percent of all Android devices (phones/tablets). While neither us nor the Kernel security team have observed any exploit targeting this vulnerability in the wild, we recommend that security teams examine potentially affected devices and implement patches as soon as possible.

It says kernel 3.8 and later is vulnerable, and we’re at 3.10.

Workaround

http://rc/

Security Notices


Other Downloads


CVEs


Live chat
Online