Description
The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel through 4.14.4, when CONFIG_NLMON is enabled, does not restrict observations of Netlink messages to a single net namespace, which allows local users to obtain sensitive information by leveraging the CAP_NET_ADMIN capability to sniff an nlmon interface for all Netlink activity on the system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4073-1 | linux security update |
Debian DSA |
DSA-4082-1 | linux security update |
EUVD |
EUVD-2017-8613 | The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel through 4.14.4, when CONFIG_NLMON is enabled, does not restrict observations of Netlink messages to a single net namespace, which allows local users to obtain sensitive information by leveraging the CAP_NET_ADMIN capability to sniff an nlmon interface for all Netlink activity on the system. |
Ubuntu USN |
USN-3619-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3619-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3653-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3653-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-3655-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3655-2 | Linux kernel (Trusty HWE) vulnerabilities |
Ubuntu USN |
USN-3657-1 | Linux kernel (Raspberry Pi 2) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:51:31.636Z
Reserved: 2017-12-06T00:00:00.000Z
Link: CVE-2017-17449
No data.
Status : Modified
Published: 2017-12-07T00:29:00.350
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-17449
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN