Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
Advisories
Source ID Title
EUVD EUVD EUVD-2016-4187 Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
Ubuntu USN Ubuntu USN USN-2930-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-2930-2 Linux kernel (Wily HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-2930-3 Linux kernel (Raspberry Pi 2) vulnerabilities
Ubuntu USN Ubuntu USN USN-3054-1 Linux kernel (Xenial HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3055-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3056-1 Linux kernel (Raspberry Pi 2) vulnerabilities
Ubuntu USN Ubuntu USN USN-3057-1 Linux kernel (Qualcomm Snapdragon) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00178}

epss

{'score': 0.00174}


cve-icon MITRE

Status: PUBLISHED

Assigner: microfocus

Published:

Updated: 2024-08-05T23:47:57.230Z

Reserved: 2016-03-13T00:00:00

Link: CVE-2016-3135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-04-27T17:59:23.850

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-3135

cve-icon Redhat

Severity : Low

Publid Date: 2016-03-10T00:00:00Z

Links: CVE-2016-3135 - Bugzilla

cve-icon OpenCVE Enrichment

No data.