6.9 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
7 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
0.0004 Low
EPSS
Percentile
10.1%
Severity: Low
Date : 2017-03-13
CVE-ID : CVE-2017-2636
Package : linux-grsec
Type : privilege escalation
Remote : No
Link : https://security.archlinux.org/AVG-201
The package linux-grsec before version 1:4.9.14.r201703121245-1 is
vulnerable to privilege escalation.
Upgrade to 1:4.9.14.r201703121245-1.
The problem has been fixed upstream in version 4.9.14.r201703121245.
n_hdlc.conf
A race condition flaw was found in the N_HLDC Linux kernel driver when
accessing the n_hdlc.tbuf list that can lead to double free. A local,
unprivileged user able to set the HDLC line discipline on the tty
device could use this flaw to crash the system or increase their
privileges on the system.
A local attacker is able to escalate privileges or crash the system if
the n_hdlc kernel module has already been explicitly loaded by an
administrator.
https://bugs.archlinux.org/task/53242
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=82f2341c94d270421f383641b7cd670e474db56b
http://seclists.org/oss-sec/2017/q1/569
https://security.archlinux.org/CVE-2017-2636
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ArchLinux | any | any | linux-grsec | <Β 1:4.9.14.r201703121245-1 | UNKNOWN |
6.9 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
7 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
0.0004 Low
EPSS
Percentile
10.1%