FPII-2319: Elevation of privilege vulnerability in kernel netfilter subsystem CVE-2016-3134 A-28940694

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
The fix is designed to add an additional check in the unconditional function.

Change-Id: I46129d08c0ea4f149da2c92a930d00ba32aeaa7b
3 files changed