PT-2017-14092 · Linux+2 · Linux Kernel+2

Dmitry Vyukov

·

Published

2017-10-05

·

Updated

2018-07-09

·

CVE-2017-15537

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.13.5
Description The issue concerns the x86/fpu subsystem in the Linux kernel, which does not correctly handle attempts to set reserved bits in the xstate header via the ptrace() or rt sigreturn() system call when a processor supports the xsave feature but not the xsaves feature. This allows local users to read the FPU registers of other processes on the system.
Recommendations For Linux kernel versions prior to 4.13.5, update to version 4.13.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the ptrace() and rt sigreturn() system calls to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2378
ALT-PU-2018-1991
CVE-2017-15537
USN-3469-1
USN-3469-2
USN-3487-1

Affected Products

Alt Linux
Linux Kernel
Ubuntu