Vulnerability identifier: #VU8131
Vulnerability risk: Low
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-125
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists in net/xfrm/xfrm_policy.c due to it does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less when CONFIG_XFRM_MIGRATE is enabled. A local attacker can submit a specially crafted XFRM_MSG_MIGRATE xfrm Netlink message and cause the service to crash.
Mitigation
Update to version 4.12.4.
Vulnerable software versions
Linux kernel: 4.12 - 4.12.3
CPE
External links
http://source.android.com/security/bulletin/pixel/2017-11-01
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?