PT-2017-14686 · Linux+1 · Linux Kernel+1

CVE-2017-17053

·

Publicado

2017-08-30

·

Atualizado

2023-06-21

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.12.10
Description The issue arises from the init new context function in the Linux kernel, which does not correctly handle errors from LDT table allocation when forking a new process. This allows a local attacker to achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program. The vulnerability is specific to kernels built with CONFIG MODIFY LDT SYSCALL=y.
Recommendations For versions prior to 4.12.10, update to version 4.12.10 or later to resolve the issue. As a temporary workaround, consider disabling the init new context function or restricting the use of CONFIG MODIFY LDT SYSCALL=y until a patch is available.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2130
ALT-PU-2017-2131
CVE-2017-17053
SUSE-SU-2018:2413-1

Produtos afetados

Alt Linux
Linux Kernel