PT-2017-1184 · Linux+2 · Linux Kernel+2
Adam Mariš
·
Published
2017-01-10
·
Updated
2023-02-28
·
CVE-2017-5546
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 4.8.x through 4.9.x before 4.9.5
Linux kernel version 4.9.x before 4.9.5
Description
The freelist-randomization feature in the Linux kernel allows local users to cause a denial of service, resulting in duplicate freelist entries and system crash, or possibly have unspecified other impact in opportunistic circumstances by leveraging the selection of a large value for a random number. This issue is related to errors in number processing.
Recommendations
For Linux kernel versions 4.8.x through 4.9.x before 4.9.5, update to version 4.9.5 or later to resolve the issue.
For Linux kernel version 4.9.x before 4.9.5, update to version 4.9.5 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Ubuntu