PT-2017-2033 · Linux+5 · Linux Kernel+5

Andrey Konovalov

+1

·

Published

2017-05-10

·

Updated

2025-09-29

·

CVE-2017-8890

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.10.15
Description The issue is related to the inet csk clone lock function in the Linux kernel, which can be exploited to cause a denial of service due to a double free error. This can be achieved by leveraging the use of the accept system call. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Linux kernel versions prior to 4.10.15, update to a version 4.10.15 or later to resolve the issue. As a temporary workaround, consider restricting the use of the accept system call to minimize the risk of exploitation.

Exploit

Fix

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-1699
ALT-PU-2017-1808
ALT-PU-2017-1854
BDU:2017-01200
CESA-2017_1842
CESA-2018_1854
CVE-2017-8890
DLA-993-1
DSA-3886-1
ELSA-2017-1842
ELSA-2017-1842-1
ELSA-2017-3574
ELSA-2017-3575
ELSA-2017-3576
ELSA-2018-1854
MGASA-2017-0186
MGASA-2017-0187
MGASA-2017-0188
OPENSUSE-SU-2017_1513-1
RHSA-2017:1842
RHSA-2017:2077
RHSA-2017:2669
RHSA-2017_1842
RHSA-2017_2077
RHSA-2018:1854
RHSA-2018_1854
SUSE-SU-2017:1853-1
SUSE-SU-2017:1990-1
SUSE-SU-2017:2043-1
SUSE-SU-2017:2046-1
SUSE-SU-2017:2049-1
SUSE-SU-2017:2060-1
SUSE-SU-2017:2061-1
SUSE-SU-2017:2062-1
SUSE-SU-2017:2063-1
SUSE-SU-2017:2064-1
SUSE-SU-2017:2065-1
SUSE-SU-2017:2066-1
SUSE-SU-2017:2067-1
SUSE-SU-2017:2068-1
SUSE-SU-2017:2070-1
SUSE-SU-2017:2072-1
SUSE-SU-2017:2073-1
SUSE-SU-2017:2088-1
SUSE-SU-2017:2089-1
SUSE-SU-2017:2090-1
SUSE-SU-2017:2091-1
SUSE-SU-2017:2092-1
SUSE-SU-2017:2094-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2389-1
SUSE-SU-2017:2446-1
SUSE-SU-2017:2447-1
SUSE-SU-2017:2448-1
SUSE-SU-2017:2525-1
SUSE-SU-2017:2791-1
SUSE-SU-2017:2908-1
SUSE-SU-2017:2920-1
SUSE-SU-2017_1853-1
SUSE-SU-2017_2089-1
SUSE-SU-2017_2090-1
SUSE-SU-2017_2091-1
SUSE-SU-2017_2094-1
SUSE-SU-2017_2389-1
SUSE-SU-2017_2446-1
SUSE-SU-2017_2447-1
SUSE-SU-2017_2448-1
SUSE-SU-2017_2791-1
USN-3342-1
USN-3342-2
USN-3343-1
USN-3343-2
USN-3344-1
USN-3344-2
USN-3345-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu