CVE-2017-7184

Advisory lineage Upstream: 0 Downstream: 44
Modified
Published: 19 Mar 2017, 18:00
Last modified:05 Aug 2024, 15:56

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
2.66% LOW
3% probability +0.78%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Mar 2017, 18:00
Published
Vulnerability first disclosed
05 Aug 2024, 15:56
Last Modified
Vulnerability information updated

Description

The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 2.66% Percentile: 86%

Affected Systems

  • linuxlinux_kernel

    4.8 | < 3.2.89 | ≥ 3.3, < 3.10.106 | ≥ 3.11, < 3.12.73 | ≥ 3.13, < 3.16.44 | ≥ 3.17, < 3.18.49 | ≥ 3.19, < 4.1.49 | ≥ 4.2, < 4.4.59 | ≥ 4.5, < 4.9.20 | ≥ 4.10, < 4.10.8

References (15)