Use-after-free error in Linux kernel - CVE-2017-16939

 

Use-after-free error in Linux kernel - CVE-2017-16939

Published: December 8, 2017 / Updated: June 17, 2021


Vulnerability identifier: #VU9601
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16939
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel due to use-after-free error. A local attacker can make a specially crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages, trigger memory corruption and cause the service to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

Linux kernel
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - TUS
SUSE Linux
Ubuntu

MRG Realtime
kernel-rt (Red Hat package)
kernel (Red Hat package)

How to mitigate CVE-2017-16939

Update to version 4.13.11.

kernel-rt (Red Hat package) - addressed in versions 3.10.0-693.47.2.rt56.641.el6rt, 3.10.0-862.2.3.rt56.806.el7
kernel (Red Hat package) - update to 3.10.0-693.47.2.el7

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins