The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-922-1 | linux security update |
EUVD |
EUVD-2017-16222 | The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52. |
Ubuntu USN |
USN-3248-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3249-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3249-2 | Linux kernel (Xenial HWE) vulnerability |
Ubuntu USN |
USN-3250-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3250-2 | Linux kernel (Trusty HWE) vulnerability |
Ubuntu USN |
USN-3251-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3251-2 | Linux kernel (HWE) vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:56:35.949Z
Reserved: 2017-03-19T00:00:00
Link: CVE-2017-7184
No data.
Status : Deferred
Published: 2017-03-19T18:59:00.193
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7184
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN