PT-2017-2626 · Linux+5 · Linux Kernel+5

Published

2017-07-07

·

Updated

2025-09-29

·

CVE-2017-7533

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 4.12.4
Description The issue is related to a race condition in the fsnotify implementation. It allows local users to gain privileges or cause a denial of service, such as memory corruption, by leveraging the simultaneous execution of the inotify handle event and vfs rename functions through a crafted application.
Recommendations For Linux kernel versions through 4.12.4, consider applying a patch or updating to a version that fixes the fsnotify implementation issue to prevent exploitation. As a temporary workaround, consider restricting access to the inotify handle event and vfs rename functions to minimize the risk of exploitation.

Exploit

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-1983
ALT-PU-2017-1992
BDU:2017-01846
CESA-2017_2473
CVE-2017-7533
DSA-3927-1
DSA-3945-1
ELSA-2017-2473
ELSA-2017-2473-1
ELSA-2017-3605
OPENSUSE-SU-2017_2110-1
OPENSUSE-SU-2017_2112-1
RHSA-2017:2473
RHSA-2017:2585
RHSA-2017:2669
RHSA-2017:2770
RHSA-2017:2869
RHSA-2017_2473
RHSA-2017_2585
SUSE-SU-2017:2041-1
SUSE-SU-2017:2042-1
SUSE-SU-2017:2043-1
SUSE-SU-2017:2046-1
SUSE-SU-2017:2049-1
SUSE-SU-2017:2060-1
SUSE-SU-2017:2061-1
SUSE-SU-2017:2062-1
SUSE-SU-2017:2063-1
SUSE-SU-2017:2064-1
SUSE-SU-2017:2065-1
SUSE-SU-2017:2066-1
SUSE-SU-2017:2067-1
SUSE-SU-2017:2068-1
SUSE-SU-2017:2069-1
SUSE-SU-2017:2070-1
SUSE-SU-2017:2072-1
SUSE-SU-2017:2073-1
SUSE-SU-2017:2074-1
SUSE-SU-2017:2088-1
SUSE-SU-2017:2089-1
SUSE-SU-2017:2090-1
SUSE-SU-2017:2091-1
SUSE-SU-2017:2092-1
SUSE-SU-2017:2093-1
SUSE-SU-2017:2094-1
SUSE-SU-2017:2095-1
SUSE-SU-2017:2096-1
SUSE-SU-2017:2098-1
SUSE-SU-2017:2099-1
SUSE-SU-2017:2100-1
SUSE-SU-2017:2102-1
SUSE-SU-2017:2103-1
SUSE-SU-2017:2114-1
SUSE-SU-2017:2286-1
SUSE-SU-2017:2342-1
SUSE-SU-2017:2389-1
SUSE-SU-2017:2525-1
SUSE-SU-2017:2956-1
SUSE-SU-2017_2041-1
SUSE-SU-2017_2042-1
SUSE-SU-2017_2074-1
SUSE-SU-2017_2098-1
SUSE-SU-2017_2100-1
SUSE-SU-2017_2102-1
SUSE-SU-2017_2103-1
SUSE-SU-2017_2286-1
USN-3377-1
USN-3377-2
USN-3378-1
USN-3378-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu