Lucene search

K
redhatcveRedhat.comRH:CVE-2017-17449
HistoryDec 14, 2017 - 2:19 a.m.

CVE-2017-17449

2017-12-1402:19:51
redhat.com
access.redhat.com
28

0.0004 Low

EPSS

Percentile

10.1%

The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel, through 4.14.4, does not restrict observations of Netlink messages to a single net namespace, when CONFIG_NLMON is enabled. This allows local users to obtain sensitive information by leveraging the CAP_NET_ADMIN capability to sniff an nlmon interface for all Netlink activity on the system.