ID:6389 - Exploit for Use-after-free error in Linux kernel - CVE-2017-16939

 
Main Vulnerability Database Exploits ID:6389 - Exploit for Use-after-free error in Linux kernel - CVE-2017-16939

ID:6389 - Exploit for Use-after-free error in Linux kernel - CVE-2017-16939

Published: June 17, 2021


Vulnerability identifier: #VU9601
Vulnerability risk: Low
CVE-ID: CVE-2017-16939
CWE-ID: CWE-416
Exploitation vector: Local access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel due to use-after-free error. A local attacker can make a specially crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages, trigger memory corruption and cause the service to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Update to version 4.13.11.