PT-2017-2425 · Linux+2 · Linux Kernel+2

Pengfei Wang

·

Publicado

2017-06-28

·

Atualizado

2023-02-24

·

CVE-2017-9984

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.11.8
Description The issue is related to the snd msnd interrupt function in the Linux kernel, which allows local users to cause a denial of service or possibly have other unspecified impacts. This is due to a "double fetch" vulnerability, where the value of a message queue head pointer can be changed between two kernel reads, resulting in over-boundary access. The vulnerability may be exploited to cause a denial of service or other effects.
Recommendations For Linux kernel versions prior to 4.11.8, update to version 4.11.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the snd msnd interrupt function to minimize the risk of exploitation.

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2206
ALT-PU-2017-2208
BDU:2017-01628
CVE-2017-9984
USN-3469-1
USN-3469-2
USN-3754-1

Produtos afetados

Alt Linux
Linux Kernel
Ubuntu