7.8

CVE-2017-17806

The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 3.2.97
Linux ≫ Linux Kernel Version >= 3.3 < 3.16.52
Linux ≫ Linux Kernel Version >= 3.17 < 3.18.89
Linux ≫ Linux Kernel Version >= 3.19 < 4.1.49
Linux ≫ Linux Kernel Version >= 4.2 < 4.4.107
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.71
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.8
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Opensuse ≫ Leap Version 42.2
Opensuse Project ≫ Leap Version 42.3
Suse ≫ Linux Enterprise Desktop Version 12 Update sp2
Suse ≫ Linux Enterprise Desktop Version 12 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update extra
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp2
Suse ≫ Linux Enterprise Server Version 12 Update sp3
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 17.10
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.424
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://usn.ubuntu.com/3583-1/
Third Party Advisory
https://usn.ubuntu.com/3583-2/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
Patch
Third Party Advisory
Issue Tracking
https://usn.ubuntu.com/3619-1/
Third Party Advisory
https://usn.ubuntu.com/3619-2/
Third Party Advisory
https://usn.ubuntu.com/3617-1/
Third Party Advisory
https://usn.ubuntu.com/3617-2/
Third Party Advisory
https://usn.ubuntu.com/3617-3/
Third Party Advisory
https://www.debian.org/security/2017/dsa-4073
Third Party Advisory
https://www.debian.org/security/2018/dsa-4082
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2948
Third Party Advisory
https://usn.ubuntu.com/3632-1/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/01/msg00004.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
Patch
Third Party Advisory
Issue Tracking
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
Patch
Third Party Advisory
Issue Tracking
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
Patch
Third Party Advisory
Issue Tracking
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
Third Party Advisory
Issue Tracking
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8
Release Notes
Issue Tracking
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=af3ff8045bbf3e32f1a448542e73abb4c8ceb6f1
Patch
http://www.securityfocus.com/bid/102293
Third Party Advisory
VDB Entry
https://github.com/torvalds/linux/commit/af3ff8045bbf3e32f1a448542e73abb4c8ceb6f1
Patch