4.9

CVE-2017-15129

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.0 < 4.14.11
Linux ≫ Linux Kernel Version 4.15 Update rc1
Linux ≫ Linux Kernel Version 4.15 Update rc2
Linux ≫ Linux Kernel Version 4.15 Update rc3
Linux ≫ Linux Kernel Version 4.15 Update rc4
Fedoraproject ≫ Fedora Version 27
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 17.10
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.274
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

https://access.redhat.com/errata/RHSA-2018:0676
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1062
Third Party Advisory
https://usn.ubuntu.com/3619-1/
Third Party Advisory
https://usn.ubuntu.com/3619-2/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0654
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1946
Third Party Advisory
https://usn.ubuntu.com/3617-1/
Third Party Advisory
https://usn.ubuntu.com/3617-2/
Third Party Advisory
https://usn.ubuntu.com/3617-3/
Third Party Advisory
https://usn.ubuntu.com/3632-1/
Third Party Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=21b5944350052d2583e82dd59b19a9ba94a007f0
Patch
http://seclists.org/oss-sec/2018/q1/7
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/102485
Broken Link
https://access.redhat.com/security/cve/CVE-2017-15129
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1531174
Patch
Third Party Advisory
Issue Tracking
https://github.com/torvalds/linux/commit/21b5944350052d2583e82dd59b19a9ba94a007f0
Patch
https://marc.info/?l=linux-netdev&m=151370451121029&w=2
Patch
Third Party Advisory
Mailing List
https://marc.info/?t=151370468900001&r=1&w=2
Third Party Advisory
Mailing List
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.11
Release Notes