PT-2017-2476 · Linux+5 · Linux Kernel+5

Geneblue

·

Published

2017-07-09

·

Updated

2025-09-29

·

CVE-2017-11176

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 4.11.9
Description The issue is related to the mq notify function in the Linux kernel, which does not set the sock pointer to NULL upon entry into the retry logic. This allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact during a user-space close of a Netlink socket. The vulnerability can be exploited by a remote attacker to cause a denial of service or other impact.
Recommendations For Linux kernel versions through 4.11.9, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-1887
ALT-PU-2017-1888
BDU:2017-01686
CESA-2017_2930
CVE-2017-11176
DLA-1099-1
DSA-3927-1
DSA-3945-1
ELSA-2017-2930
ELSA-2017-2930-1
ELSA-2017-3632
ELSA-2017-3633
ELSA-2018-0169
RHSA-2017:2918
RHSA-2017:2930
RHSA-2017:2931
RHSA-2017_2930
RHSA-2017_2931
RHSA-2018:0169
RHSA-2018:3822
RHSA-2018_0169
RHSA-2018_3822
SUSE-SU-2017:2342-1
SUSE-SU-2017:2389-1
SUSE-SU-2017:2525-1
SUSE-SU-2017:2908-1
SUSE-SU-2017:2920-1
USN-3405-1
USN-3405-2
USN-3468-1
USN-3468-2
USN-3468-3
USN-3470-1
USN-3470-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu