Wind River Support Network

HomeDefectsLIN7-11312
Fixed

LIN7-11312 : Security Advisory - linux - CVE-2017-18509

Created: Aug 13, 2019    Updated: Jul 1, 2020
Resolved Date: Oct 17, 2019
Found In Version: 7.0.0.1
Fix Version: 7.0.0.31
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Kernel

Description

An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2017-18509 User=admin}

CVEs


Live chat
Online