critical remote-attackable CVE-2016-7117 in kernel/net: Fix use after free in the recvmmsg exit path [released]

Tracked by Jolla (In release)

CVSS Base Score3: 9.8 critical remote


Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

patch is available, so please fix it as soon as possible...

The question has been closed for the following reason "released in a software update" by lpr
@lpr Thank you for efforts of reporting vulnerabilities!

@jovirkku how about a "tracked by jolla" in this case, too?

@lpr : released inämsänjoki

