The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembly, which allows local users to cause a denial of service (integer overflow, out-of-bounds write, and GPF) or possibly have unspecified other impact via a crafted application that makes socket, connect, and writev system calls, related to net/ipv6/netfilter/nfconntrackreasm.c and net/ipv6/netfilter/nfdefragipv6_hooks.c.
[
{
"id": "CVE-2016-9755-505eb3d0",
"signature_version": "v1",
"digest": {
"function_hash": "157530722457512719752179307453340582161",
"length": 1158.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Function",
"target": {
"file": "net/ipv6/netfilter/nf_conntrack_reasm.c",
"function": "nf_ct_frag6_gather"
}
},
{
"id": "CVE-2016-9755-8167113b",
"signature_version": "v1",
"digest": {
"function_hash": "336822152819507084244745434053641655714",
"length": 376.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Function",
"target": {
"file": "net/ipv6/netfilter/nf_defrag_ipv6_hooks.c",
"function": "ipv6_defrag"
}
},
{
"id": "CVE-2016-9755-9aa0debe",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"130563406806358796491076850627249568322",
"336123891536056814396579223610628177620",
"283581081005182457716194605766120073135",
"240096839100467659906509048036615844263",
"47507775360231556691290106336131082811",
"244571885056084226638244355682997436484",
"317968636760399675437870229483936788974"
]
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Line",
"target": {
"file": "net/ipv6/netfilter/nf_conntrack_reasm.c"
}
},
{
"id": "CVE-2016-9755-eaa6ba1a",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"51828134798211376880133786770902594501",
"120011688912548925149202802733151418338",
"102538152242483321997723214847678188947",
"64637121970511333858747711942762992628"
]
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Line",
"target": {
"file": "net/ipv6/netfilter/nf_defrag_ipv6_hooks.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9755.json"
[
{
"id": "CVE-2016-9755-06d84d90",
"signature_version": "v1",
"digest": {
"function_hash": "336822152819507084244745434053641655714",
"length": 376.0
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Function",
"target": {
"file": "net/ipv6/netfilter/nf_defrag_ipv6_hooks.c",
"function": "ipv6_defrag"
}
},
{
"id": "CVE-2016-9755-0a80e303",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"51828134798211376880133786770902594501",
"120011688912548925149202802733151418338",
"102538152242483321997723214847678188947",
"64637121970511333858747711942762992628"
]
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Line",
"target": {
"file": "net/ipv6/netfilter/nf_defrag_ipv6_hooks.c"
}
},
{
"id": "CVE-2016-9755-73a93a1f",
"signature_version": "v1",
"digest": {
"function_hash": "157530722457512719752179307453340582161",
"length": 1158.0
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Function",
"target": {
"file": "net/ipv6/netfilter/nf_conntrack_reasm.c",
"function": "nf_ct_frag6_gather"
}
},
{
"id": "CVE-2016-9755-d94b807a",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"130563406806358796491076850627249568322",
"336123891536056814396579223610628177620",
"283581081005182457716194605766120073135",
"240096839100467659906509048036615844263",
"47507775360231556691290106336131082811",
"244571885056084226638244355682997436484",
"317968636760399675437870229483936788974"
]
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/9b57da0630c9fd36ed7a20fc0f98dc82cc0777fa",
"signature_type": "Line",
"target": {
"file": "net/ipv6/netfilter/nf_conntrack_reasm.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9755.json"