kernel: net: double-free and memory corruption in get_net_ns_by_id()
Published Jan 9, 2018
4.7
MEDIUMCVSS 3.1
EPSS 0.36%
Description
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.
Affected products
- Vendor n/a Product Linux kernel v4.0-rc1 through v4.15-rc5 Defaultn/a
- Version Linux kernel v4.0-rc1 through v4.15-rc5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Linux kernel v4.0-rc1 through v4.15-rc5 | n/a |
|
Configuration 1
- ≥ 4.0 · < 4.14.11
- 4.15
- 4.15
- 4.15
- 4.15
Configuration 2
- 27
Configuration 3
- 14.04
- 16.04
- 17.10
Configuration 4
- 7.0
- 7.4
- 7.0
- 7.4
- 7.6
- 7.7
- 7.0
- 7.4
- 7.0
- 7.4
- 7.4
- 7.0
- 7
- 7.0
- 7.0
- 7.4
- 7.4
- 7.6
- 7.7
- 7.4
- 7.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-862.el7
Fixed · RHSA-2018:1062
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-49.el7a
Fixed · RHSA-2018:0654
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-862.rt56.804.el7
Fixed · RHSA-2018:0676
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.55.1.el7
Fixed · RHSA-2019:1946
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-862.el7 | Fixed | RHSA-2018:1062 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-49.el7a | Fixed | RHSA-2018:0654 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-862.rt56.804.el7 | Fixed | RHSA-2018:0676 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.55.1.el7 | Fixed | RHSA-2019:1946 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and 6 as the code with the flaw is not present in the products listed. This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 7, its real-time kernel, Red Hat Enterprise MRG 2, Red Hat Enterprise Linux 7 for ARM 64 and Red Hat Enterprise Linux 7 for Power 9 LE. Future updates for the respective releases may address this issue.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.36% (0.00357) | 27.11th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.36% (0.00360) | 27.59th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00036) | 7.13th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.81% (0.01806) | 35.10th | v1 |
| Jan 6, 2022 | 1.81% (0.01806) | 34.41th | v1 |
| Sep 1, 2021 | 1.81% (0.01806) | 74.38th | v1 |
| Apr 14, 2021 | 1.81% (0.01806) | 0.00th | v1 |
References (21)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=21b5944350052d2583e82dd59b19a9ba94a007f0 x_refsource_MISCPatch
- http://seclists.org/oss-sec/2018/q1/7 x_refsource_MISCMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/102485 vdb-entryx_refsource_BIDBroken Link
- https://access.redhat.com/errata/RHSA-2018:0654 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0676 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1062 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1946 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-15129 x_refsource_MISCThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1531174 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/21b5944350052d2583e82dd59b19a9ba94a007f0 x_refsource_MISCPatch
- https://marc.info/?l=linux-netdev&m=151370451121029&w=2 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://marc.info/?t=151370468900001&r=1&w=2 x_refsource_MISCMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-15129
- https://usn.ubuntu.com/3617-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3617-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3617-3/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3619-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3619-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3632-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-15129
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.11 x_refsource_MISCRelease Notes
Change history (0)
No recorded changes yet.