Memory corruption in Linux kernel - CVE-2017-1000255

 

Memory corruption in Linux kernel - CVE-2017-1000255

Published: October 12, 2017 / Updated: October 16, 2017


Vulnerability identifier: #VU8812
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000255
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code with escalated privileges.

The vulnerability exists due to a boundary error in the Linux kernel's when handling signal frame on PowerPC systems. A malicious local user process could craft a signal frame allowing an attacker to corrupt memory and execute arbitrary code on the target system with escalated privileges.

Affected software

Linux kernel
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Ubuntu
Fedora

kernel-alt (Red Hat package)
kernel

How to mitigate CVE-2017-1000255

Update to Linux kernel 4.9.55 or 4.13.6.

kernel-alt (Red Hat package) - update to 4.14.0-49.el7a
kernel - addressed in versions 4.13.6-100.fc25, 4.13.6-200.fc26, 4.13.6-300.fc27, 4.13.8-100.fc25, 4.13.8-200.fc26, 4.13.8-300.fc27

External References

Related Security Bulletins