PT-2017-2268 · Linux+5 · Linux Kernel+5

Andrey Konovalov

·

Published

2017-03-28

·

Updated

2026-05-22

·

CVE-2017-7308

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.10.6
Description The issue is caused by a signedness error in the packet set ring function in the Linux kernel, which allows local users to cause a denial of service or gain privileges if the CAP NET RAW capability is held. This is due to improper validation of certain block-size data, leading to an out-of-bounds write. The vulnerability can be exploited via crafted system calls.
Recommendations For Linux kernel versions prior to 4.10.6, update to a version 4.10.6 or later to resolve the issue. As a temporary workaround, consider disabling the packet set ring function until a patch is available. Restrict access to the CAP NET RAW capability to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-1600
ALT-PU-2017-1601
BDU:2017-01465
CESA-2017_1308
CESA-2018_1854
CVE-2017-7308
DLA-922-1
ELSA-2017-1308
ELSA-2017-1308-1
ELSA-2017-3579
ELSA-2017-3580
ELSA-2017-3637
ELSA-2018-1854
MGASA-2017-0136
MGASA-2017-0147
MGASA-2017-0148
OPENSUSE-SU-2017_1140-1
OPENSUSE-SU-2017_1215-1
RHSA-2017:1297
RHSA-2017:1298
RHSA-2017:1308
RHSA-2017_1298
RHSA-2017_1308
RHSA-2018:1854
RHSA-2018_1854
SUSE-SU-2017:1059-1
SUSE-SU-2017:1060-1
SUSE-SU-2017:1064-1
SUSE-SU-2017:1183-1
SUSE-SU-2017:1247-1
SUSE-SU-2017:1277-1
SUSE-SU-2017:1278-1
SUSE-SU-2017:1279-1
SUSE-SU-2017:1280-1
SUSE-SU-2017:1281-1
SUSE-SU-2017:1283-1
SUSE-SU-2017:1284-1
SUSE-SU-2017:1285-1
SUSE-SU-2017:1287-1
SUSE-SU-2017:1288-1
SUSE-SU-2017:1289-1
SUSE-SU-2017:1290-1
SUSE-SU-2017:1291-1
SUSE-SU-2017:1293-1
SUSE-SU-2017:1294-1
SUSE-SU-2017:1295-1
SUSE-SU-2017:1297-1
SUSE-SU-2017:1299-1
SUSE-SU-2017:1300-1
SUSE-SU-2017:1301-1
SUSE-SU-2017:1302-1
SUSE-SU-2017:1303-1
SUSE-SU-2017:1308-1
SUSE-SU-2017:1360-1
SUSE-SU-2017:1990-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2525-1
SUSE-SU-2017_1278-1
SUSE-SU-2017_1281-1
SUSE-SU-2017_1285-1
SUSE-SU-2017_1287-1
SUSE-SU-2017_1291-1
SUSE-SU-2017_1299-1
SUSE-SU-2017_1300-1
SUSE-SU-2017_1302-1
USN-3256-1
USN-3256-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu