Assertion failure in Linux kernel - CVE-2017-5986
Published: February 18, 2017 / Updated: February 19, 2017
Vulnerability details
The vulnerability allows a local user to cause kernel panic.
The vulnerability exists due to a race condition in the sctp_wait_for_sndbuf() function in net/sctp/socket.c in the Linux kernel before 4.9.11. A local user can use userspace application to trigger a BUG_ON() system call if the socket tx buffer is full and cause kernel panic.
Successful exploitation of this vulnerability may result in denial of service condition.
Affected software
CentOS
SUSE Linux
Ubuntu
Fedora
kernel (Red Hat package)
kernel
How to mitigate CVE-2017-5986
kernel - addressed in versions 4.9.9-100.fc24, 4.9.9-200.fc25
External References
Related Security Bulletins
- Local denial of service in Linux kernel
- SUSE Linux update for Linux kernel
- Red Hat Linux update for kernel
- CentOS 7 update for kernel
- Ubuntu update for Linux kernel (HWE)
- Ubuntu update for Linux kernel
- Ubuntu update for Linux kernel (Trusty HWE)
- Ubuntu update for Linux kernel
- Fedora 25 update for kernel
- Fedora 24 update for kernel