Security restrictions bypass in Linux kernel - CVE-2017-1000370
Published: August 23, 2017 / Updated: September 14, 2018
Vulnerability identifier: #VU8003
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000370
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local attacker to bypass security restrictions on the target system.
The weakness exists due to a flaw in offset2lib patch. A local attacker can send a specially-crafted request, bypass security restrictions and gain full access to the system.
The weakness exists due to a flaw in offset2lib patch. A local attacker can send a specially-crafted request, bypass security restrictions and gain full access to the system.
Affected software
Linux kernel
Amazon Linux AMI
Fedora
kernel
Juniper Junos Space
Amazon Linux AMI
Fedora
kernel
Juniper Junos Space
How to mitigate CVE-2017-1000370
Update to version 4.11.6.
kernel - addressed in versions 4.11.6-100.fc24, 4.11.6-101.fc24, 4.11.6-200.fc25, 4.11.6-201.fc25, 4.11.6-300.fc26, 4.11.6-301.fc26
Juniper Junos Space - update to 20.3R1
Juniper Junos Space - update to 20.3R1