PT-2017-17770 · Linux+4 · Linux Kernel+4

Huang Weller

·

Published

2016-06-22

·

Updated

2023-02-12

·

CVE-2017-7495

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.6.2
Description The issue allows local users to obtain sensitive information from other users' files under specific circumstances. This can happen when the ext4 data=ordered mode is used and a needs-flushing-before-commit list is mishandled. The exploitation involves waiting for a hardware reset, creating a new file, making write system calls, and then reading this file.
Recommendations For Linux kernel versions prior to 4.6.2, update to version 4.6.2 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1634
ALT-PU-2017-1330
CESA-2017_1842
CVE-2017-7495
RHSA-2017:1842
RHSA-2017:2077
RHSA-2017:2669
RHSA-2017_1842
RHSA-2017_2077
USN-3405-1
USN-3405-2
USN-3406-1
USN-3406-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu