Wind River Support Network

HomeDefectsSCP7-842
Fixed

SCP7-842 : Security Advisory - linux - CVE-2017-7482

Created: Jun 29, 2018    Updated: Oct 26, 2018
Resolved Date: Aug 14, 2018
Found In Version: 7.0.0.28
Fix Version: 7.0.0.29
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Kernel

Description

When a kerberos 5 ticket is being decoded so that it can be loaded into an rxrpc-type key, the length of a variable-length field is checked to make sure that it's not going to overrun the allocated buffer space. The data is padded to the nearest four-byte boundary and the code doesn't check for this extra four-byte aligned padding.  This can lead to the size-remaining variable wrapping and the data pointer accessing or reading past the end of the buffer.  The read functionality could allow for a 3 byte infoleak and the write flaw could allow for an uncontrolled 3 byte write to kernels slab memory.  This could lead to memory corruption and possible privilege escalation although no known exploit exists at the time of writing.

https://nvd.nist.gov/vuln/detail/CVE-2017-7482 

Other Downloads


Live chat
Online