Input validation error in Linux kernel - CVE-2017-1000379

 

Input validation error in Linux kernel - CVE-2017-1000379

Published: June 19, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38830
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000379
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.


Affected software

Linux kernel
Fedora
kernel

How to mitigate CVE-2017-1000379

Install update from vendor's website.

kernel - addressed in versions 4.11.6-100.fc24, 4.11.6-101.fc24, 4.11.6-200.fc25, 4.11.6-201.fc25, 4.11.6-300.fc26, 4.11.6-301.fc26

External References

Related Security Bulletins