1
PublicDateAtUSN: 2016-04-20
2
Candidate: CVE-2016-3955
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3955
6
http://www.openwall.com/lists/oss-security/2016/04/19/1
7
https://git.kernel.org/linus/b348d7dddb6c4fbfc810b7a0626e8ec9e29f7cbb
8
https://usn.ubuntu.com/usn/usn-2965-1
9
https://usn.ubuntu.com/usn/usn-2965-4
10
https://usn.ubuntu.com/usn/usn-2965-3
11
https://usn.ubuntu.com/usn/usn-2965-2
12
https://usn.ubuntu.com/usn/usn-2989-1
13
https://usn.ubuntu.com/usn/usn-2996-1
14
https://usn.ubuntu.com/usn/usn-2997-1
15
https://usn.ubuntu.com/usn/usn-2998-1
16
https://usn.ubuntu.com/usn/usn-3000-1
17
https://usn.ubuntu.com/usn/usn-3001-1
18
https://usn.ubuntu.com/usn/usn-3002-1
19
https://usn.ubuntu.com/usn/usn-3003-1
20
https://usn.ubuntu.com/usn/usn-3004-1
22
The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the
23
Linux kernel before 4.5.3 allows remote attackers to cause a denial of
24
service (out-of-bounds write) or possibly have unspecified other impact via
25
a crafted length value in a USB/IP packet.
27
It was discovered that an out-of-bounds write could occur when handling
28
incoming packets in the USB/IP implementation in the Linux kernel. A remote
29
attacker could use this to cause a denial of service (system crash) or
30
possibly execute arbitrary code.
32
jdstrand> android kernels (flo, goldfish, grouper, maguro, mako and manta) are
33
not supported on the Ubuntu Touch 14.10 and earlier preview kernels
34
jdstrand> linux-lts-saucy no longer receives official support
35
jdstrand> linux-lts-quantal no longer receives official support
36
sbeattie> driver moved from staging in 3.17
38
https://launchpad.net/bugs/1572666
44
break-fix: - b348d7dddb6c4fbfc810b7a0626e8ec9e29f7cbb
45
upstream_linux: released (4.6~rc3)
46
precise_linux: released (3.2.0-104.145)
47
precise/esm_linux: released (3.2.0-104.145)
48
trusty_linux: released (3.13.0-87.133)
49
vivid/ubuntu-core_linux: released (3.19.0-61.69)
50
vivid/stable-phone-overlay_linux: DNE
51
wily_linux: released (4.2.0-38.45)
52
xenial_linux: released (4.4.0-22.39)
53
yakkety_linux: not-affected (4.4.0-22.39)
54
zesty_linux: not-affected (4.8.0-22.24)
55
devel_linux: not-affected (4.10.0-19.21)
57
Patches_linux-ti-omap4:
58
upstream_linux-ti-omap4: released (4.6~rc3)
59
precise_linux-ti-omap4: released (3.2.0-1482.109)
60
precise/esm_linux-ti-omap4: DNE (precise was released [3.2.0-1482.109])
61
trusty_linux-ti-omap4: DNE
62
vivid/ubuntu-core_linux-ti-omap4: DNE
63
vivid/stable-phone-overlay_linux-ti-omap4: DNE
64
wily_linux-ti-omap4: DNE
65
xenial_linux-ti-omap4: DNE
66
yakkety_linux-ti-omap4: DNE
67
zesty_linux-ti-omap4: DNE
68
devel_linux-ti-omap4: DNE
70
Patches_linux-linaro-omap:
71
upstream_linux-linaro-omap: released (4.6~rc3)
72
precise_linux-linaro-omap: ignored (abandoned)
73
precise/esm_linux-linaro-omap: DNE (precise was ignored [abandoned])
74
trusty_linux-linaro-omap: DNE
75
vivid/ubuntu-core_linux-linaro-omap: DNE
76
vivid/stable-phone-overlay_linux-linaro-omap: DNE
77
wily_linux-linaro-omap: DNE
78
xenial_linux-linaro-omap: DNE
79
yakkety_linux-linaro-omap: DNE
80
zesty_linux-linaro-omap: DNE
81
devel_linux-linaro-omap: DNE
83
Patches_linux-linaro-shared:
84
upstream_linux-linaro-shared: released (4.6~rc3)
85
precise_linux-linaro-shared: ignored (abandoned)
86
precise/esm_linux-linaro-shared: DNE (precise was ignored [abandoned])
87
trusty_linux-linaro-shared: DNE
88
vivid/ubuntu-core_linux-linaro-shared: DNE
89
vivid/stable-phone-overlay_linux-linaro-shared: DNE
90
wily_linux-linaro-shared: DNE
91
xenial_linux-linaro-shared: DNE
92
yakkety_linux-linaro-shared: DNE
93
zesty_linux-linaro-shared: DNE
94
devel_linux-linaro-shared: DNE
96
Patches_linux-linaro-vexpress:
97
upstream_linux-linaro-vexpress: released (4.6~rc3)
98
precise_linux-linaro-vexpress: ignored (abandoned)
99
precise/esm_linux-linaro-vexpress: DNE (precise was ignored [abandoned])
100
trusty_linux-linaro-vexpress: DNE
101
vivid/ubuntu-core_linux-linaro-vexpress: DNE
102
vivid/stable-phone-overlay_linux-linaro-vexpress: DNE
103
wily_linux-linaro-vexpress: DNE
104
xenial_linux-linaro-vexpress: DNE
105
yakkety_linux-linaro-vexpress: DNE
106
zesty_linux-linaro-vexpress: DNE
107
devel_linux-linaro-vexpress: DNE
109
Patches_linux-qcm-msm:
110
upstream_linux-qcm-msm: released (4.6~rc3)
111
precise_linux-qcm-msm: ignored (abandoned)
112
precise/esm_linux-qcm-msm: DNE (precise was ignored [abandoned])
113
trusty_linux-qcm-msm: DNE
114
vivid/ubuntu-core_linux-qcm-msm: DNE
115
vivid/stable-phone-overlay_linux-qcm-msm: DNE
116
wily_linux-qcm-msm: DNE
117
xenial_linux-qcm-msm: DNE
118
yakkety_linux-qcm-msm: DNE
119
zesty_linux-qcm-msm: DNE
120
devel_linux-qcm-msm: DNE
122
Tags_linux-armadaxp: not-ue
123
Patches_linux-armadaxp:
124
upstream_linux-armadaxp: released (4.6~rc3)
125
precise_linux-armadaxp: released (3.2.0-1667.92)
126
precise/esm_linux-armadaxp: DNE (precise was released [3.2.0-1667.92])
127
trusty_linux-armadaxp: DNE
128
vivid/ubuntu-core_linux-armadaxp: DNE
129
vivid/stable-phone-overlay_linux-armadaxp: DNE
130
wily_linux-armadaxp: DNE
131
xenial_linux-armadaxp: DNE
132
yakkety_linux-armadaxp: DNE
133
zesty_linux-armadaxp: DNE
134
devel_linux-armadaxp: DNE
136
Tags_linux-lts-quantal: not-ue
137
Patches_linux-lts-quantal: DNE
138
upstream_linux-lts-quantal: released (4.6~rc3)
139
precise_linux-lts-quantal: ignored (end-of-life)
140
precise/esm_linux-lts-quantal: DNE (precise was ignored [end-of-life])
141
trusty_linux-lts-quantal: DNE
142
vivid/ubuntu-core_linux-lts-quantal: DNE
143
vivid/stable-phone-overlay_linux-lts-quantal: DNE
144
wily_linux-lts-quantal: DNE
145
xenial_linux-lts-quantal: DNE
146
yakkety_linux-lts-quantal: DNE
147
zesty_linux-lts-quantal: DNE
148
devel_linux-lts-quantal: DNE
150
Patches_linux-lts-raring:
151
upstream_linux-lts-raring: released (4.6~rc3)
152
precise_linux-lts-raring: ignored (end-of-life)
153
precise/esm_linux-lts-raring: DNE (precise was ignored [end-of-life])
154
trusty_linux-lts-raring: DNE
155
vivid/ubuntu-core_linux-lts-raring: DNE
156
vivid/stable-phone-overlay_linux-lts-raring: DNE
157
wily_linux-lts-raring: DNE
158
xenial_linux-lts-raring: DNE
159
yakkety_linux-lts-raring: DNE
160
zesty_linux-lts-raring: DNE
161
devel_linux-lts-raring: DNE
163
Tags_linux-lts-saucy: not-ue
164
Patches_linux-lts-saucy:
165
upstream_linux-lts-saucy: released (4.6~rc3)
166
precise_linux-lts-saucy: ignored (end-of-life)
167
precise/esm_linux-lts-saucy: DNE (precise was ignored [end-of-life])
168
trusty_linux-lts-saucy: DNE
169
vivid/ubuntu-core_linux-lts-saucy: DNE
170
vivid/stable-phone-overlay_linux-lts-saucy: DNE
171
wily_linux-lts-saucy: DNE
172
xenial_linux-lts-saucy: DNE
173
yakkety_linux-lts-saucy: DNE
174
zesty_linux-lts-saucy: DNE
175
devel_linux-lts-saucy: DNE
177
Patches_linux-lts-trusty:
178
upstream_linux-lts-trusty: released (4.6~rc3)
179
precise_linux-lts-trusty: released (3.13.0-88.135~precise1)
180
precise/esm_linux-lts-trusty: released (3.13.0-88.135~precise1)
181
trusty_linux-lts-trusty: DNE
182
vivid/ubuntu-core_linux-lts-trusty: DNE
183
vivid/stable-phone-overlay_linux-lts-trusty: DNE
184
wily_linux-lts-trusty: DNE
185
xenial_linux-lts-trusty: DNE
186
yakkety_linux-lts-trusty: DNE
187
zesty_linux-lts-trusty: DNE
188
devel_linux-lts-trusty: DNE
190
Patches_linux-goldfish:
191
upstream_linux-goldfish: released (4.6~rc3)
192
precise_linux-goldfish: DNE
193
precise/esm_linux-goldfish: DNE
194
trusty_linux-goldfish: ignored
195
vivid/ubuntu-core_linux-goldfish: DNE
196
vivid/stable-phone-overlay_linux-goldfish: DNE
197
wily_linux-goldfish: ignored (reached end-of-life)
198
xenial_linux-goldfish: ignored (abandoned)
199
yakkety_linux-goldfish: ignored (abandoned)
200
zesty_linux-goldfish: ignored (abandoned)
201
devel_linux-goldfish: DNE
203
Patches_linux-grouper:
204
upstream_linux-grouper: released (4.6~rc3)
205
precise_linux-grouper: DNE
206
precise/esm_linux-grouper: DNE
207
trusty_linux-grouper: ignored
208
vivid/ubuntu-core_linux-grouper: DNE
209
vivid/stable-phone-overlay_linux-grouper: DNE
210
wily_linux-grouper: DNE
211
xenial_linux-grouper: DNE
212
yakkety_linux-grouper: DNE
213
zesty_linux-grouper: DNE
214
devel_linux-grouper: DNE
216
Patches_linux-maguro:
217
upstream_linux-maguro: released (4.6~rc3)
218
precise_linux-maguro: DNE
219
precise/esm_linux-maguro: DNE
220
trusty_linux-maguro: ignored
221
vivid/ubuntu-core_linux-maguro: DNE
222
vivid/stable-phone-overlay_linux-maguro: DNE
223
wily_linux-maguro: DNE
224
xenial_linux-maguro: DNE
225
yakkety_linux-maguro: DNE
226
zesty_linux-maguro: DNE
227
devel_linux-maguro: DNE
230
upstream_linux-mako: released (4.6~rc3)
231
precise_linux-mako: DNE
232
precise/esm_linux-mako: DNE
233
trusty_linux-mako: ignored
234
vivid/ubuntu-core_linux-mako: DNE
235
vivid/stable-phone-overlay_linux-mako: ignored (abandoned)
236
wily_linux-mako: ignored (reached end-of-life)
237
xenial_linux-mako: ignored (abandoned)
238
yakkety_linux-mako: ignored (abandoned)
239
zesty_linux-mako: DNE
240
devel_linux-mako: DNE
243
upstream_linux-manta: released (4.6~rc3)
244
precise_linux-manta: DNE
245
precise/esm_linux-manta: DNE
246
trusty_linux-manta: ignored
247
vivid/ubuntu-core_linux-manta: DNE
248
vivid/stable-phone-overlay_linux-manta: DNE
249
wily_linux-manta: ignored (reached end-of-life)
250
xenial_linux-manta: DNE
251
yakkety_linux-manta: DNE
252
zesty_linux-manta: DNE
253
devel_linux-manta: DNE
256
upstream_linux-flo: released (4.6~rc3)
257
precise_linux-flo: DNE
258
precise/esm_linux-flo: DNE
259
trusty_linux-flo: ignored
260
vivid/ubuntu-core_linux-flo: DNE
261
vivid/stable-phone-overlay_linux-flo: ignored (abandoned)
262
wily_linux-flo: ignored (reached end-of-life)
263
xenial_linux-flo: ignored (abandoned)
264
yakkety_linux-flo: ignored (abandoned)
268
Patches_linux-raspi2:
269
upstream_linux-raspi2: released (4.6~rc3)
270
precise_linux-raspi2: DNE
271
precise/esm_linux-raspi2: DNE
272
trusty_linux-raspi2: DNE
273
vivid/ubuntu-core_linux-raspi2: ignored (was pending now end-of-life)
274
vivid/stable-phone-overlay_linux-raspi2: DNE
275
wily_linux-raspi2: released (4.2.0-1031.41)
276
xenial_linux-raspi2: released (4.4.0-1010.12)
277
yakkety_linux-raspi2: not-affected (4.4.0-1010.12)
278
zesty_linux-raspi2: not-affected (4.8.0-1013.15)
279
devel_linux-raspi2: not-affected (4.10.0-1004.6)
281
Patches_linux-lts-utopic:
282
upstream_linux-lts-utopic: released (4.6~rc3)
283
precise_linux-lts-utopic: DNE
284
precise/esm_linux-lts-utopic: DNE
285
trusty_linux-lts-utopic: released (3.16.0-73.95~14.04.1)
286
vivid/ubuntu-core_linux-lts-utopic: DNE
287
vivid/stable-phone-overlay_linux-lts-utopic: DNE
288
wily_linux-lts-utopic: DNE
289
xenial_linux-lts-utopic: DNE
290
yakkety_linux-lts-utopic: DNE
291
zesty_linux-lts-utopic: DNE
292
devel_linux-lts-utopic: DNE
294
Patches_linux-lts-vivid:
295
upstream_linux-lts-vivid: released (4.6~rc3)
296
precise_linux-lts-vivid: DNE
297
precise/esm_linux-lts-vivid: DNE
298
trusty_linux-lts-vivid: released (3.19.0-61.69~14.04.1)
299
vivid/ubuntu-core_linux-lts-vivid: DNE
300
vivid/stable-phone-overlay_linux-lts-vivid: DNE
301
wily_linux-lts-vivid: DNE
302
xenial_linux-lts-vivid: DNE
303
yakkety_linux-lts-vivid: DNE
304
zesty_linux-lts-vivid: DNE
305
devel_linux-lts-vivid: DNE
307
Patches_linux-lts-wily:
308
upstream_linux-lts-wily: released (4.6~rc3)
309
precise_linux-lts-wily: DNE
310
precise/esm_linux-lts-wily: DNE
311
trusty_linux-lts-wily: released (4.2.0-38.45~14.04.1)
312
vivid/ubuntu-core_linux-lts-wily: DNE
313
vivid/stable-phone-overlay_linux-lts-wily: DNE
314
wily_linux-lts-wily: DNE
315
xenial_linux-lts-wily: DNE
316
yakkety_linux-lts-wily: DNE
317
zesty_linux-lts-wily: DNE
318
devel_linux-lts-wily: DNE
320
Patches_linux-krillin:
321
product_linux-krillin: ignored (was needed now end-of-life)
323
Patches_linux-vegetahd:
324
product_linux-vegetahd: ignored (was needed now end-of-life)
326
Patches_linux-lts-xenial:
327
upstream_linux-lts-xenial: released (4.6~rc3)
328
precise_linux-lts-xenial: DNE
329
precise/esm_linux-lts-xenial: DNE
330
trusty_linux-lts-xenial: released (4.4.0-22.39~14.04.1)
331
vivid/ubuntu-core_linux-lts-xenial: DNE
332
vivid/stable-phone-overlay_linux-lts-xenial: DNE
333
wily_linux-lts-xenial: DNE
334
xenial_linux-lts-xenial: DNE
335
yakkety_linux-lts-xenial: DNE
336
zesty_linux-lts-xenial: DNE
337
devel_linux-lts-xenial: DNE
339
Patches_linux-snapdragon:
340
upstream_linux-snapdragon: released (4.6~rc3)
341
precise_linux-snapdragon: DNE
342
precise/esm_linux-snapdragon: DNE
343
trusty_linux-snapdragon: DNE
344
vivid/ubuntu-core_linux-snapdragon: DNE
345
vivid/stable-phone-overlay_linux-snapdragon: DNE
346
wily_linux-snapdragon: DNE
347
xenial_linux-snapdragon: released (4.4.0-1013.14)
348
yakkety_linux-snapdragon: not-affected (4.4.0-1013.14)
349
zesty_linux-snapdragon: not-affected (4.4.0-1029.32)
350
devel_linux-snapdragon: not-affected (4.4.0-1050.54)
353
upstream_linux-aws: released (4.6~rc3)
354
precise_linux-aws: DNE
355
precise/esm_linux-aws: DNE
356
trusty_linux-aws: not-affected (4.4.0-1002.2)
357
vivid/ubuntu-core_linux-aws: DNE
358
vivid/stable-phone-overlay_linux-aws: DNE
359
xenial_linux-aws: not-affected (4.4.0-1001.10)
360
yakkety_linux-aws: DNE
364
Patches_linux-hwe-edge:
365
upstream_linux-hwe-edge: released (4.6~rc3)
366
precise_linux-hwe-edge: DNE
367
precise/esm_linux-hwe-edge: DNE
368
trusty_linux-hwe-edge: DNE
369
vivid/ubuntu-core_linux-hwe-edge: DNE
370
vivid/stable-phone-overlay_linux-hwe-edge: DNE
371
xenial_linux-hwe-edge: not-affected (4.8.0-28.30~16.04.1)
372
yakkety_linux-hwe-edge: DNE
373
zesty_linux-hwe-edge: DNE
374
devel_linux-hwe-edge: DNE
377
upstream_linux-hwe: released (4.6~rc3)
378
precise_linux-hwe: DNE
379
precise/esm_linux-hwe: DNE
380
trusty_linux-hwe: DNE
381
vivid/ubuntu-core_linux-hwe: DNE
382
vivid/stable-phone-overlay_linux-hwe: DNE
383
xenial_linux-hwe: not-affected (4.8.0-36.36~16.04.1)
384
yakkety_linux-hwe: DNE
389
upstream_linux-gke: released (4.6~rc3)
390
precise_linux-gke: DNE
391
precise/esm_linux-gke: DNE
392
trusty_linux-gke: DNE
393
vivid/ubuntu-core_linux-gke: DNE
394
vivid/stable-phone-overlay_linux-gke: DNE
395
xenial_linux-gke: not-affected (4.4.0-1003.3)
396
yakkety_linux-gke: DNE