CVE-2016-3699
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.
- CVSS 3.0
- 7.4 HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- linux/linux kernel · redhat/enterprise mrg · redhat/linux
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-2574.html
- http://rhn.redhat.com/errata/RHSA-2016-2584.html
- http://www.openwall.com/lists/oss-security/2016/09/22/4Third Party Advisory
- http://www.securityfocus.com/bid/93114Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=1329653Issue Tracking, Patch, Third Party Advisory, VDB Entry
- https://github.com/mjg59/linux/commit/a4a5ed2835e8ea042868b7401dced3f517cafa76Exploit
- http://rhn.redhat.com/errata/RHSA-2016-2574.html
- http://rhn.redhat.com/errata/RHSA-2016-2584.html
- http://www.openwall.com/lists/oss-security/2016/09/22/4Third Party Advisory
- http://www.securityfocus.com/bid/93114Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=1329653Issue Tracking, Patch, Third Party Advisory, VDB Entry
- https://github.com/mjg59/linux/commit/a4a5ed2835e8ea042868b7401dced3f517cafa76Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.