PT-2017-1184 · Linux+2 · Linux Kernel+2

Adam Mariš

·

Published

2017-01-10

·

Updated

2023-02-28

·

CVE-2017-5546

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 4.8.x through 4.9.x before 4.9.5 Linux kernel version 4.9.x before 4.9.5
Description The freelist-randomization feature in the Linux kernel allows local users to cause a denial of service, resulting in duplicate freelist entries and system crash, or possibly have unspecified other impact in opportunistic circumstances by leveraging the selection of a large value for a random number. This issue is related to errors in number processing.
Recommendations For Linux kernel versions 4.8.x through 4.9.x before 4.9.5, update to version 4.9.5 or later to resolve the issue. For Linux kernel version 4.9.x before 4.9.5, update to version 4.9.5 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1063
BDU:2017-00295
CVE-2017-5546
USN-3361-1

Affected Products

Alt Linux
Linux Kernel
Ubuntu