Lucene search

K
f5F5F5:K30737254
HistoryJul 13, 2018 - 12:00 a.m.

K30737254 : Linux kernel vulnerability CVE-2017-2671

2018-07-1300:00:00
my.f5.com
26

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

Security Advisory Description

The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call. (CVE-2017-2671)

Impact

A local attacker can cause a denial of service (DoS) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.