PT-2017-18732 · Linux+3 · Linux Kernel+3

Jann Horn

·

Publicado

2017-04-13

·

Atualizado

2018-07-09

·

CVE-2017-9150

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.11.1
Description The issue concerns the do check function in the Linux kernel, which fails to restrict the output of sensitive address information. This allows local users to obtain sensitive address information via crafted bpf system calls. The do check function in kernel/bpf/verifier.c is specifically implicated, as it does not make the allow ptr leaks value available for restricting the output of the print bpf insn function.
Recommendations For Linux kernel versions prior to 4.11.1, update to version 4.11.1 or later to resolve the issue.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1469
ALT-PU-2018-1991
CVE-2017-9150
OPENSUSE-SU-2017_1513-1
SUSE-SU-2017:1853-1
SUSE-SU-2017:1990-1
USN-3345-1
USN-3359-1
USN-3361-1
USN-3364-1
USN-3364-2
USN-3364-3

Produtos afetados

Alt Linux
Linux Kernel
Suse
Ubuntu