CVE-2017-7979
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized memory access and refcount underflow, and system hang or crash) or possibly have unspecified other impact via "tc filter add" commands in certain contexts. NOTE: this does not affect stable kernels, such as 4.10.x, from kernel.org.
La característica cookie en la implementación del paquete de acción API en net/sched/act_api.c en el kernel de Linux 4.11.x hasta la versión 4.11-rc7 no maneja adecuadamente el array tb nlattr, lo que permite a usuarios locales provocar una denegación de servicio (acceso a memoria no inicializado y desbordamiento inferior de conteo de referencias y cuelgue o caída de sistema) o posiblemente tener otro impacto no especificado a través de comandos "tc filter add" en ciertos contextos. NOTA: esto no afecta a kernels estables, como 4.10.x, de kernel.org.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-19 CVE Reserved
- 2017-04-19 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97969 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://marc.info/?l=linux-netdev&m=149200742616349 | 2017-04-26 | |
http://marc.info/?l=linux-netdev&m=149200746116365 | 2017-04-26 | |
http://marc.info/?l=linux-netdev&m=149200746116366 | 2017-04-26 | |
http://marc.info/?l=linux-netdev&m=149251041420194 | 2017-04-26 | |
http://marc.info/?l=linux-netdev&m=149251041420195 | 2017-04-26 | |
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1682368 | 2017-04-26 | |
https://bugzilla.proxmox.com/show_bug.cgi?id=1351 | 2017-04-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.11 Search vendor "Linux" for product "Linux Kernel" and version "4.11" | rc1 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.11 Search vendor "Linux" for product "Linux Kernel" and version "4.11" | rc2 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.11 Search vendor "Linux" for product "Linux Kernel" and version "4.11" | rc3 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.11 Search vendor "Linux" for product "Linux Kernel" and version "4.11" | rc4 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.11 Search vendor "Linux" for product "Linux Kernel" and version "4.11" | rc5 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.11 Search vendor "Linux" for product "Linux Kernel" and version "4.11" | rc6 |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.11 Search vendor "Linux" for product "Linux Kernel" and version "4.11" | rc7 |
Affected
|