PT-2017-2626 · Linux+5 · Linux Kernel+5

Publicado

2017-07-07

·

Atualizado

2025-09-29

·

CVE-2017-7533

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 4.12.4
Description The issue is related to a race condition in the fsnotify implementation. It allows local users to gain privileges or cause a denial of service, such as memory corruption, by leveraging the simultaneous execution of the inotify handle event and vfs rename functions through a crafted application.
Recommendations For Linux kernel versions through 4.12.4, consider applying a patch or updating to a version that fixes the fsnotify implementation issue to prevent exploitation. As a temporary workaround, consider restricting access to the inotify handle event and vfs rename functions to minimize the risk of exploitation.

Exploit

Correção

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2017-1983
ALT-PU-2017-1992
BDU:2017-01846
CESA-2017_2473
CVE-2017-7533
DSA-3927-1
DSA-3945-1
ELSA-2017-2473
ELSA-2017-2473-1
ELSA-2017-3605
OPENSUSE-SU-2017_2110-1
OPENSUSE-SU-2017_2112-1
RHSA-2017:2473
RHSA-2017:2585
RHSA-2017:2669
RHSA-2017:2770
RHSA-2017:2869
RHSA-2017_2473
RHSA-2017_2585
SUSE-SU-2017:2041-1
SUSE-SU-2017:2042-1
SUSE-SU-2017:2043-1
SUSE-SU-2017:2046-1
SUSE-SU-2017:2049-1
SUSE-SU-2017:2060-1
SUSE-SU-2017:2061-1
SUSE-SU-2017:2062-1
SUSE-SU-2017:2063-1
SUSE-SU-2017:2064-1
SUSE-SU-2017:2065-1
SUSE-SU-2017:2066-1
SUSE-SU-2017:2067-1
SUSE-SU-2017:2068-1
SUSE-SU-2017:2069-1
SUSE-SU-2017:2070-1
SUSE-SU-2017:2072-1
SUSE-SU-2017:2073-1
SUSE-SU-2017:2074-1
SUSE-SU-2017:2088-1
SUSE-SU-2017:2089-1
SUSE-SU-2017:2090-1
SUSE-SU-2017:2091-1
SUSE-SU-2017:2092-1
SUSE-SU-2017:2093-1
SUSE-SU-2017:2094-1
SUSE-SU-2017:2095-1
SUSE-SU-2017:2096-1
SUSE-SU-2017:2098-1
SUSE-SU-2017:2099-1
SUSE-SU-2017:2100-1
SUSE-SU-2017:2102-1
SUSE-SU-2017:2103-1
SUSE-SU-2017:2114-1
SUSE-SU-2017:2286-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2389-1
SUSE-SU-2017:2525-1
SUSE-SU-2017:2956-1
SUSE-SU-2017_2041-1
SUSE-SU-2017_2042-1
SUSE-SU-2017_2074-1
SUSE-SU-2017_2098-1
SUSE-SU-2017_2100-1
SUSE-SU-2017_2102-1
SUSE-SU-2017_2103-1
SUSE-SU-2017_2286-1
USN-3377-1
USN-3377-2
USN-3378-1
USN-3378-2

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu