CVE-2016-1880

NameCVE-2016-1880
DescriptionThe Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs811278

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kfreebsd-10 (PTS)jessie10.1~svn274115-4vulnerable
stretch10.3~svn300087-3fixed
buster10.3~svn300087-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kfreebsd-10source(unstable)10.3~svn296373-1unimportant811278
kfreebsd-9sourcewheezy(unfixed)end-of-life
kfreebsd-9source(unstable)(unfixed)

Notes

kfreebsd not covered by security support in Jessie
[wheezy] - kfreebsd-9 <end-of-life> (Unsupported in wheezy-lts)

Search for package or bug name: Reporting problems