PT-2017-2359 · Linux+5 · Linux Kernel+5

Alexander Popov

·

Published

2017-02-07

·

Updated

2019-10-03

·

CVE-2017-5986

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.9.11
Description The issue is related to a race condition in the sctp wait for sndbuf function in net/sctp/socket.c. This can be exploited by a local user via a multithreaded application that peels off an association in a certain buffer-full state, leading to a denial of service (assertion failure and panic). The vulnerability exists due to insufficient checking of the resource state when it can be shared.
Recommendations For Linux kernel versions prior to 4.9.11, update to version 4.9.11 or later to resolve the issue. As a temporary workaround, consider restricting the use of multithreaded applications that could exploit this condition until a patch is applied.

Fix

DoS

Assertion Failure

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1210
ALT-PU-2017-1330
BDU:2017-01558
CESA-2017_1308
CVE-2017-5986
DLA-849-1
DSA-3804-1
MGASA-2017-0063
MGASA-2017-0064
MGASA-2017-0065
OPENSUSE-SU-2017_0541-1
OPENSUSE-SU-2017_0547-1
RHSA-2017:1308
RHSA-2017_1308
SUSE-SU-2017:0575-1
SUSE-SU-2017:1247-1
SUSE-SU-2017:1301-1
SUSE-SU-2017:1360-1
SUSE-SU-2017:1990-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2525-1
USN-3264-1
USN-3264-2
USN-3265-1
USN-3265-2
USN-3266-1
USN-3266-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu