PT-2017-12368 · Linux+3 · Linux Kernel+3
Bo Zhang
·
Published
2017-09-20
·
Updated
2024-06-15
·
CVE-2017-12153
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 4.13.3
Description
A security issue was found in the nl80211 set rekey data() function, which does not check for required attributes in a Netlink request. This request can be issued by a user with the CAP NET ADMIN capability, potentially resulting in a NULL pointer dereference and system crash.
Recommendations
For Linux kernel versions prior to 4.13.3, consider updating to a version that includes the fix for this issue to prevent potential system crashes. As a temporary workaround, consider restricting the CAP NET ADMIN capability to minimize the risk of exploitation.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Suse
Ubuntu