PT-2017-2359 · Linux+5 · Linux Kernel+5
Alexander Popov
·
Publicado
2017-02-07
·
Atualizado
2019-10-03
·
CVE-2017-5986
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 4.9.11
Description
The issue is related to a race condition in the
sctp wait for sndbuf function in net/sctp/socket.c. This can be exploited by a local user via a multithreaded application that peels off an association in a certain buffer-full state, leading to a denial of service (assertion failure and panic). The vulnerability exists due to insufficient checking of the resource state when it can be shared.Recommendations
For Linux kernel versions prior to 4.9.11, update to version 4.9.11 or later to resolve the issue. As a temporary workaround, consider restricting the use of multithreaded applications that could exploit this condition until a patch is applied.
Correção
DoS
Assertion Failure
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu