Lucene search

K
f5F5F5:K31209433
HistoryApr 13, 2017 - 12:00 a.m.

K31209433 : Linux kernel vulnerabilities CVE-2017-6345, CVE-2017-6347, and CVE-2017-6348

2017-04-1300:00:00
my.f5.com
39

AI Score

6.6

Confidence

High

EPSS

0

Percentile

5.1%

Security Advisory Description

The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certain destructor exists in required circumstances, which allows local users to cause a denial of service (BUG_ON) or possibly have unspecified other impact via crafted system calls."

The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, which allows local users to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted system calls, as demonstrated by use of the MSG_MORE flag in conjunction with loopback UDP transmission."

The hashbin_delete function in net/irda/irqueue.c in the Linux kernel before 4.9.13 improperly manages lock dropping, which allows local users to cause a denial of service (deadlock) via crafted operations on IrDA devices."
Impact
There is no impact; F5 products are not affected by this vulnerability.