Vulnerability Name: | CVE-2016-2085 (CCN-113821) | ||||||||||||||||||||
Assigned: | 2016-01-27 | ||||||||||||||||||||
Published: | 2016-01-27 | ||||||||||||||||||||
Updated: | 2016-12-03 | ||||||||||||||||||||
Summary: | The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack. | ||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-19 | ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-2085 Source: CCN Type: Linux Kernel GIT Repository EVM: Use crypto_memneq() for digest comparisons Source: CONFIRM Type: Vendor Advisory http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=613317bd212c585c20796c10afe5daaa95d4b0a1 Source: UBUNTU Type: UNKNOWN USN-2946-1 Source: UBUNTU Type: UNKNOWN USN-2946-2 Source: UBUNTU Type: UNKNOWN USN-2947-1 Source: UBUNTU Type: UNKNOWN USN-2947-2 Source: UBUNTU Type: UNKNOWN USN-2947-3 Source: UBUNTU Type: UNKNOWN USN-2948-1 Source: UBUNTU Type: UNKNOWN USN-2948-2 Source: UBUNTU Type: UNKNOWN USN-2949-1 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=1324867 Source: XF Type: UNKNOWN linux-kernel-cve20162085-sec-bypass(113821) Source: CONFIRM Type: Patch, Vendor Advisory https://github.com/torvalds/linux/commit/613317bd212c585c20796c10afe5daaa95d4b0a1 Source: CONFIRM Type: UNKNOWN https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2085.html Source: CONFIRM Type: UNKNOWN https://security-tracker.debian.org/tracker/CVE-2016-2085 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-2085 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |