PT-2017-2033 · Linux+5 · Linux Kernel+5

Andrey Konovalov

+1

·

Publicado

2017-05-10

·

Atualizado

2025-09-29

·

CVE-2017-8890

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.10.15
Description The issue is related to the inet csk clone lock function in the Linux kernel, which can be exploited to cause a denial of service due to a double free error. This can be achieved by leveraging the use of the accept system call. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Linux kernel versions prior to 4.10.15, update to a version 4.10.15 or later to resolve the issue. As a temporary workaround, consider restricting the use of the accept system call to minimize the risk of exploitation.

Exploit

Correção

DoS

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2017-1699
ALT-PU-2017-1808
ALT-PU-2017-1854
BDU:2017-01200
CESA-2017_1842
CESA-2018_1854
CVE-2017-8890
DLA-993-1
DSA-3886-1
ELSA-2017-1842
ELSA-2017-1842-1
ELSA-2017-3574
ELSA-2017-3575
ELSA-2017-3576
ELSA-2018-1854
MGASA-2017-0186
MGASA-2017-0187
MGASA-2017-0188
OPENSUSE-SU-2017_1513-1
RHSA-2017:1842
RHSA-2017:2077
RHSA-2017:2669
RHSA-2017_1842
RHSA-2017_2077
RHSA-2018:1854
RHSA-2018_1854
SUSE-SU-2017:1853-1
SUSE-SU-2017:1990-1
SUSE-SU-2017:2043-1
SUSE-SU-2017:2046-1
SUSE-SU-2017:2049-1
SUSE-SU-2017:2060-1
SUSE-SU-2017:2061-1
SUSE-SU-2017:2062-1
SUSE-SU-2017:2063-1
SUSE-SU-2017:2064-1
SUSE-SU-2017:2065-1
SUSE-SU-2017:2066-1
SUSE-SU-2017:2067-1
SUSE-SU-2017:2068-1
SUSE-SU-2017:2070-1
SUSE-SU-2017:2072-1
SUSE-SU-2017:2073-1
SUSE-SU-2017:2088-1
SUSE-SU-2017:2089-1
SUSE-SU-2017:2090-1
SUSE-SU-2017:2091-1
SUSE-SU-2017:2092-1
SUSE-SU-2017:2094-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2389-1
SUSE-SU-2017:2446-1
SUSE-SU-2017:2447-1
SUSE-SU-2017:2448-1
SUSE-SU-2017:2525-1
SUSE-SU-2017:2791-1
SUSE-SU-2017:2908-1
SUSE-SU-2017:2920-1
SUSE-SU-2017_1853-1
SUSE-SU-2017_2089-1
SUSE-SU-2017_2090-1
SUSE-SU-2017_2091-1
SUSE-SU-2017_2094-1
SUSE-SU-2017_2389-1
SUSE-SU-2017_2446-1
SUSE-SU-2017_2447-1
SUSE-SU-2017_2448-1
SUSE-SU-2017_2791-1
USN-3342-1
USN-3342-2
USN-3343-1
USN-3343-2
USN-3344-1
USN-3344-2
USN-3345-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu