kernel: Heap out-of-bounds read in AF_PACKET sockets
Published Oct 4, 2017
7.8
HIGHCVSS 3.1
EPSS 0.37%
Description
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.
Affected products
No data.
Configuration 1
- ≥ 2.6.27 · < 3.2.92
- ≥ 3.3 · < 3.10.108
- ≥ 3.11 · < 3.16.47
- ≥ 3.17 · < 3.18.65
- ≥ 3.19 · < 4.1.44
- ≥ 4.2 · < 4.4.82
- ≥ 4.5 · < 4.9.43
- ≥ 4.10 · < 4.12.7
Configuration 2
- 5.0
- 6.0
- 7.0
Configuration 3
- 6.0
- 7.0
- 6.0
- 7.0
- 7.4
- 7.6
- 7.4
- 7.5
- 7.6
- 7.4
- 7.6
- 6.0
- 7.0
Configuration 4
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-696.16.1.el6
Fixed · RHSA-2017:3200
Red Hat Enterprise Linux 7
kernel-0:3.10.0-693.5.2.el7
Fixed · RHSA-2017:2930
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-693.5.2.rt56.626.el7
Fixed · RHSA-2017:2931
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.5.2.rt56.592.el6rt
Fixed · RHSA-2017:2918
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-696.16.1.el6 | Fixed | RHSA-2017:3200 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-693.5.2.el7 | Fixed | RHSA-2017:2930 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-693.5.2.rt56.626.el7 | Fixed | RHSA-2017:2931 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.5.2.rt56.592.el6rt | Fixed | RHSA-2017:2918 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7, and MRG-2. Future Linux kernel updates for the respective releases may address this issue.
References (12)
- http://www.debian.org/security/2017/dsa-3981 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/100267 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039132 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2918 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2930 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2931 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3200 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000111 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2017-1000111 x_refsource_CONFIRMThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1479304 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000111
- https://www.cve.org/CVERecord?id=CVE-2017-1000111
Change history (0)
No recorded changes yet.