CVE-2017-18509

Advisory lineage Upstream: 0 Downstream: 10
Modified
Published: 13 Aug 2019, 13:17
Last modified:05 Aug 2024, 21:28

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.07% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

13 Aug 2019, 13:17
Published
Vulnerability first disclosed
05 Aug 2024, 21:28
Last Modified
Vulnerability information updated

Description

An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.07% Percentile: 22%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Affected Systems

  • canonicalubuntu_linux

    16.04

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • linuxlinux_kernel

    < 3.16.72 | ≥ 3.17, < 4.4.187 | ≥ 4.5, < 4.9.187 | ≥ 4.10, < 4.11

References (13)