Description
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1099-1 | linux security update |
Debian DSA |
DSA-3981-1 | linux security update |
EUVD |
EUVD-2017-1406 | Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW. |
Ubuntu USN |
USN-3384-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3384-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-3385-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3385-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3386-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3386-2 | Linux kernel (Trusty HWE) vulnerabilities |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Linux
Subscribe
Linux Kernel
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Enterprise Mrg
Subscribe
Rhel Extras Rt
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:53:06.811Z
Reserved: 2017-10-03T00:00:00.000Z
Link: CVE-2017-1000111
No data.
Status : Deferred
Published: 2017-10-05T01:29:04.430
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-1000111
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN