Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCKZAPPED status, related to net/l2tp/l2tpip.c and net/l2tp/l2tp_ip6.c.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10200.json"
[
{
"id": "CVE-2016-10200-51bcb2a9",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@32c231164b762dddefa13af5a0101032c70b50ef",
"target": {
"file": "net/l2tp/l2tp_ip.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"280804391238346148379634354039451638141",
"142557395921784793264155795208429980157",
"260091445088848084702218882706404547449",
"71476743148260574059025621904972674894",
"49335412050057475120670361236850671554",
"300379895433916719304650531201395769635",
"242544593532646212604228098562292900796",
"11133065439601217483807796553044668998",
"338498228810791172272997366089561002382"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"id": "CVE-2016-10200-8a002adf",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@32c231164b762dddefa13af5a0101032c70b50ef",
"target": {
"file": "net/l2tp/l2tp_ip6.c",
"function": "l2tp_ip6_bind"
},
"digest": {
"function_hash": "44151822839545358205419475499410142471",
"length": 1923.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-10200-a8863461",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@32c231164b762dddefa13af5a0101032c70b50ef",
"target": {
"file": "net/l2tp/l2tp_ip6.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"193561034780064139651570292689252524845",
"312202002545952117971908210338712897431",
"323384524767600778556977468976528573099",
"225138713395357841624393333508850493065",
"108500264789640958285535334558130447655",
"246017682551407968898792784126541277129",
"314048940683705811078599272995176986997",
"339594977035078080767828608606759024747",
"326578831386481599917773849892834786836"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"id": "CVE-2016-10200-cd3d1b71",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@32c231164b762dddefa13af5a0101032c70b50ef",
"target": {
"file": "net/l2tp/l2tp_ip.c",
"function": "l2tp_ip_bind"
},
"digest": {
"function_hash": "153317527354877374352760885752041739338",
"length": 1375.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
}
]