CVE-2017-5986
Vulnerability Summary
Timeline
Description
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.
CVSS Metrics
- v3.0•MEDIUM•Score: 5.5CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- v2.0•HIGH•Score: 7.1AV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 1.16%• Percentile: 66%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
- CWE-617•Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Affected Systems
- debian•linux
< 4.9.10-1 | < 4.9.10-1 | < 4.9.10-1 | < 4.9.10-1
- ubuntu•linux
< 3.13.0-117.164 | < 4.4.0-75.96
- ubuntu•linux-aws
< 4.4.0-1016.25
- ubuntu•linux-azure
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-gcp
all
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gke
< 4.4.0-1012.12 | all
- ubuntu•linux-hwe
< 4.8.0-56.61~16.04.1 | all
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-lowlatency-hwe-6.11
all
- ubuntu•linux-lts-xenial
< 4.4.0-75.96~14.04.1
- ubuntu•linux-oem
all
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1054.61 | all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1057.61
- linux•linux_kernel
≤ 4.9.11
References (17)
- https://access.redhat.com/errata/RHSA-2017:1308
- https://github.com/torvalds/linux/commit/2dcab598484185dea7ec22219c76dcdd59e3cb90
- http://www.openwall.com/lists/oss-security/2017/02/14/6
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2dcab598484185dea7ec22219c76dcdd59e3cb90
- https://bugzilla.redhat.com/show_bug.cgi?id=1420276
- http://www.securityfocus.com/bid/96222
- http://www.debian.org/security/2017/dsa-3804
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.11
- https://ubuntu.com/security/CVE-2017-5986
- https://ubuntu.com/security/notices/USN-3264-1
- https://ubuntu.com/security/notices/USN-3264-2
- https://ubuntu.com/security/notices/USN-3266-2
- https://ubuntu.com/security/notices/USN-3266-1
- https://ubuntu.com/security/notices/USN-3265-1
- https://ubuntu.com/security/notices/USN-3265-2
- https://www.cve.org/CVERecord?id=CVE-2017-5986
- https://security-tracker.debian.org/tracker/CVE-2017-5986