PT-2017-15452 · Linux+4 · Linux Kernel+4
Adam Mariš
·
Publicado
2017-02-09
·
Atualizado
2023-02-12
·
CVE-2017-2618
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 4.9.10
Description
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
Recommendations
For versions prior to 4.9.10, update to version 4.9.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the /proc/pid/attr files to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu