PT-2017-17563 · Linux+5 · Linux Kernel+5

Published

2017-03-19

·

Updated

2023-02-10

·

CVE-2017-7184

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.10.6
Description The issue allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP NET ADMIN capability. This can be achieved through the xfrm replay verify len function in net/xfrm/xfrm user.c after an XFRM MSG NEWAE update, which does not validate certain size data. The vulnerability was demonstrated during a Pwn2Own competition at CanSecWest 2017.
Recommendations For Linux kernel versions prior to 4.10.6, update to a version 4.10.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the CAP NET ADMIN capability to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2017-1398
ALT-PU-2017-1399
CESA-2017_2930
CVE-2017-7184
DLA-922-1
MGASA-2017-0097
MGASA-2017-0098
MGASA-2017-0099
OPENSUSE-SU-2017_0906-1
OPENSUSE-SU-2017_0907-1
RHSA-2017:2918
RHSA-2017:2930
RHSA-2017:2931
RHSA-2017_2930
RHSA-2017_2931
RHSA-2019:4159
SUSE-SU-2017:0864-1
SUSE-SU-2017:0865-1
SUSE-SU-2017:0866-1
SUSE-SU-2017:0867-1
SUSE-SU-2017:0868-1
SUSE-SU-2017:0869-1
SUSE-SU-2017:0870-1
SUSE-SU-2017:0871-1
SUSE-SU-2017:0872-1
SUSE-SU-2017:0873-1
SUSE-SU-2017:0874-1
SUSE-SU-2017:0875-1
SUSE-SU-2017:0876-1
SUSE-SU-2017:0877-1
SUSE-SU-2017:0878-1
SUSE-SU-2017:0879-1
SUSE-SU-2017:0880-1
SUSE-SU-2017:0881-1
SUSE-SU-2017:0882-1
SUSE-SU-2017:0883-1
SUSE-SU-2017:0884-1
SUSE-SU-2017:0885-1
SUSE-SU-2017:0886-1
SUSE-SU-2017:0887-1
SUSE-SU-2017:0888-1
SUSE-SU-2017:0889-1
SUSE-SU-2017:1301-1
SUSE-SU-2017:1990-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2525-1
SUSE-SU-2017_0873-1
SUSE-SU-2017_0875-1
SUSE-SU-2017_0876-1
SUSE-SU-2017_0880-1
SUSE-SU-2017_0881-1
SUSE-SU-2017_0888-1
SUSE-SU-2017_0889-1
USN-3248-1
USN-3249-1
USN-3249-2
USN-3250-1
USN-3250-2
USN-3251-1
USN-3251-2
ZDI-17-240

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu