Lucene search

K
cve[email protected]CVE-2017-11176
HistoryJul 11, 2017 - 11:29 p.m.

CVE-2017-11176

2017-07-1123:29:00
CWE-416
web.nvd.nist.gov
257
6
linux kernel
denial of service
netlink socket
use-after-free
cve-2017-11176
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.0%

The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.

Affected configurations

NVD
Node
linuxlinux_kernelRange<3.2.92
OR
linuxlinux_kernelRange3.3–3.16.47
OR
linuxlinux_kernelRange3.17–3.18.61
OR
linuxlinux_kernelRange3.19–4.1.43
OR
linuxlinux_kernelRange4.2–4.4.77
OR
linuxlinux_kernelRange4.5–4.9.38
OR
linuxlinux_kernelRange4.10–4.11.11
OR
linuxlinux_kernelRange4.12–4.12.2
Node
debiandebian_linuxMatch8.0
OR
debiandebian_linuxMatch9.0

Social References

More

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.0%