PT-2017-2425 · Linux+2 · Linux Kernel+2

Pengfei Wang

·

Published

2017-06-28

·

Updated

2023-02-24

·

CVE-2017-9984

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.11.8
Description The issue is related to the snd msnd interrupt function in the Linux kernel, which allows local users to cause a denial of service or possibly have other unspecified impacts. This is due to a "double fetch" vulnerability, where the value of a message queue head pointer can be changed between two kernel reads, resulting in over-boundary access. The vulnerability may be exploited to cause a denial of service or other effects.
Recommendations For Linux kernel versions prior to 4.11.8, update to version 4.11.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the snd msnd interrupt function to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2206
ALT-PU-2017-2208
BDU:2017-01628
CVE-2017-9984
USN-3469-1
USN-3469-2
USN-3754-1

Affected Products

Alt Linux
Linux Kernel
Ubuntu