PT-2017-2537 · Linux+3 · Linux Kernel+3

Publicado

2017-07-19

·

Atualizado

2023-01-19

·

CVE-2017-11473

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.3
Description The issue is caused by a buffer overflow in the mp override legacy irq() function, located in arch/x86/kernel/acpi/boot.c. This allows local users to gain privileges via a crafted ACPI table.
Recommendations For Linux kernel versions prior to 3.3, consider updating to a version that contains a fix for this issue as a permanent solution. As a temporary workaround, consider restricting access to the mp override legacy irq() function to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1952
ALT-PU-2017-1967
BDU:2017-01748
CVE-2017-11473
OPENSUSE-SU-2017_2110-1
OPENSUSE-SU-2017_2112-1
RHSA-2018:0654
SUSE-SU-2017:2286-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2389-1
SUSE-SU-2017:2525-1
SUSE-SU-2017:2869-1
SUSE-SU-2017:2956-1
USN-3754-1

Produtos afetados

Alt Linux
Linux Kernel
Suse
Ubuntu