PT-2017-2359 · Linux+5 · Linux Kernel+5
Alexander Popov
·
Published
2017-02-07
·
Updated
2019-10-03
·
CVE-2017-5986
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 4.9.11
Description
The issue is related to a race condition in the
sctp wait for sndbuf function in net/sctp/socket.c. This can be exploited by a local user via a multithreaded application that peels off an association in a certain buffer-full state, leading to a denial of service (assertion failure and panic). The vulnerability exists due to insufficient checking of the resource state when it can be shared.Recommendations
For Linux kernel versions prior to 4.9.11, update to version 4.9.11 or later to resolve the issue. As a temporary workaround, consider restricting the use of multithreaded applications that could exploit this condition until a patch is applied.
Fix
DoS
Assertion Failure
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu