Race condition in Linux kernel - CVE-2017-17712
Published: December 26, 2017 / Updated: May 30, 2020
Vulnerability identifier: #VU9772
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17712
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists due to a race condition in inet->hdrincl in the raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel. A local attacker can trigger uninitialized stack pointer usage and execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to a race condition in inet->hdrincl in the raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel. A local attacker can trigger uninitialized stack pointer usage and execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Linux kernel
Arch Linux
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
SUSE Linux
Ubuntu
Fedora
kernel-alt (Red Hat package)
kernel
Arch Linux
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
SUSE Linux
Ubuntu
Fedora
kernel-alt (Red Hat package)
kernel
How to mitigate CVE-2017-17712
Update to version 4.14.6.
Linux kernel - update to 4.2
kernel-alt (Red Hat package) - update to 4.11.0-44.6.1.el7a
kernel - addressed in versions 4.14.7-200.fc26, 4.14.7-300.fc27, 4.14.8-200.fc26
kernel-alt (Red Hat package) - update to 4.11.0-44.6.1.el7a
kernel - addressed in versions 4.14.7-200.fc26, 4.14.7-300.fc27, 4.14.8-200.fc26
External References
Related Security Bulletins
- Debian update for linux
- Arch Linux update for Linux
- Amazon Linux AMI update for kernel
- SUSE Linux update for the Linux Kernel (Live Patch 11 for SLE 12 SP2)
- SUSE Linux update for the Linux Kernel (Live Patch 3 for SLE 12 SP3)
- SUSE Linux update for the Linux Kernel (Live Patch 1 for SLE 12 SP3)
- SUSE Linux update for the Linux Kernel (Live Patch 4 for SLE 12 SP3)
- SUSE Linux update for the Linux Kernel (Live Patch 2 for SLE 12 SP3)
- SUSE Linux update for the Linux Kernel (Live Patch 7 for SLE 12 SP3)
- SUSE Linux update for the Linux Kernel (Live Patch 6 for SLE 12 SP3)
- SUSE Linux update for the Linux Kernel (Live Patch 5 for SLE 12 SP3)
- Ubuntu update for Linux kernel
- Ubuntu update for Linux kernel (HWE)
- Ubuntu update for Linux kernel (Raspberry Pi 2)
- Ubuntu update for Linux kernel
- Ubuntu update for Linux kernel (Xenial HWE)
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- Arch Linux update for linux-lts
- SUSE Linux update for the Linux Kernel
- Arch Linux update for linux-zen
- Red Hat Enterprise Linux 7 update for kernel-alt
- Fedora 27 update for kernel
- Fedora 26 update for kernel
- Fedora 26 update for kernel