CVE-2017-18270
kernel: improper keyrings creation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
En el kernel de Linux, en versiones anteriores a la 4.13.5, un usuario local podrÃa crear keyrings para otros usuarios mediante comandos keyctl, estableciendo configuraciones por defecto no deseadas o provocando una denegación de servicio (DoS).
A flaw was found in the Linux kernel in the way a local user could create keyrings for other users via keyctl commands. This may allow an attacker to set unwanted defaults, a denial of service, or possibly leak keyring information between users.
Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel did not properly validate meta block groups. An attacker with physical access could use this to specially craft an ext4 image that causes a denial of service. It was discovered that an information disclosure vulnerability existed in the ACPI implementation of the Linux kernel. A local attacker could use this to expose sensitive information. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-18 CVE Reserved
- 2018-05-18 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104254 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=1856774#c11 | X_refsource_misc | |
https://bugzilla.redhat.com/show_bug.cgi?id=1856774#c9 | X_refsource_misc | |
https://support.f5.com/csp/article/K37301725 | X_refsource_confirm | |
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1580979 | 2018-04-10 | |
https://usn.ubuntu.com/3754-1 | 2020-08-14 | |
https://access.redhat.com/security/cve/CVE-2017-18270 | 2018-04-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | < 4.13.5 Search vendor "Linux" for product "Linux Kernel" and version " < 4.13.5" | - |
Affected
|