kernel: Out-of-bounds heap access in xfrm
Published Mar 19, 2017
7.8
HIGHCVSS 3.1
EPSS 1.80%
Description
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
Affected products
No data.
Configuration 1
- 4.8
Running on/with
- 16.10
Configuration 2
- < 3.2.89
- ≥ 3.3 · < 3.10.106
- ≥ 3.11 · < 3.12.73
- ≥ 3.13 · < 3.16.44
- ≥ 3.17 · < 3.18.49
- ≥ 3.19 · < 4.1.49
- ≥ 4.2 · < 4.4.59
- ≥ 4.5 · < 4.9.20
- ≥ 4.10 · < 4.10.8
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-693.5.2.el7
Fixed · RHSA-2017:2930
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-693.5.2.rt56.626.el7
Fixed · RHSA-2017:2931
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.71.1.el7
Fixed · RHSA-2019:4159
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.71.1.el7
Fixed · RHSA-2019:4159
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.71.1.el7
Fixed · RHSA-2019:4159
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.5.2.rt56.592.el6rt
Fixed · RHSA-2017:2918
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-693.5.2.el7 | Fixed | RHSA-2017:2930 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-693.5.2.rt56.626.el7 | Fixed | RHSA-2017:2931 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.71.1.el7 | Fixed | RHSA-2019:4159 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.71.1.el7 | Fixed | RHSA-2019:4159 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.71.1.el7 | Fixed | RHSA-2019:4159 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.5.2.rt56.592.el6rt | Fixed | RHSA-2017:2918 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 as the code with the flaw is not present in the products listed. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. In a default or common use of Red Hat Enterprise Linux 7 and MRG-2 this issue does not allow an unprivileged local or remote user to elevate their privileges on the system. In order to exploit this issue the attacker needs CAP_NET_ADMIN capability, which needs to be granted especially by the administrator to the attacker's process. This in turn requires granting CAP_NET_ADMIN capability to the process' binary and/or attacker's account. Another possibility to obtain CAP_NET_ADMIN capability in Red Hat Enterprise Linux 7 for an attacker is running a process inside a user+network namespace with mapped root privileges inside the namespace. Since Red Hat Enterprise Linux 7 does not have unprivileged user namespaces enabled by default, local or remote unprivileged users also cannot abuse namespaces to grant this capability to themselves and elevate their privileges. Given the severity of this issue, future Linux kernel updates for the Red Hat Enterprise Linux 7 and MRG-2 products are planned to address it.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.80% (0.01798) | 77.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.76% (0.01759) | 74.99th | v5 (v2026.06.15) |
| Nov 21, 2025 | 1.76% (0.01765) | 82.05th | v4 (v2025.03.14) |
| Nov 18, 2025 | 0.47% (0.00468) | 61.82th | v4 (v2025.03.14) |
| Oct 13, 2025 | 2.36% (0.02356) | 84.28th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.64% (0.00643) | 68.87th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00151) | 52.74th | v3 (v2023.03.01) |
| Jun 19, 2024 | 0.15% (0.00151) | 51.52th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.11% (0.00106) | 42.51th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00074) | 30.13th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.20% (0.02196) | 50.60th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.20% (0.02196) | 0.00th | v1 |
References (19)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=677e806da4d916052585301785d847c3b3e6186a x_refsource_CONFIRMVendor Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f843ee6dd019bcece3e74e76ad9df0155655d0df x_refsource_CONFIRMVendor Advisory
- http://openwall.com/lists/oss-security/2017/03/29/2 x_refsource_CONFIRMMailing ListThird Party Advisory
- http://www.eweek.com/security/ubuntu-linux-falls-on-day-1-of-pwn2own-hacking-competition x_refsource_MISCTechnical DescriptionThird Party Advisory
- http://www.securityfocus.com/bid/97018 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038166 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2918 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2930 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2931 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4159 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-7184 Vendor Advisory
- https://blog.trendmicro.com/results-pwn2own-2017-day-one/ x_refsource_MISCTechnical DescriptionThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1435153 Issue Tracking
- https://github.com/torvalds/linux/commit/677e806da4d916052585301785d847c3b3e6186a x_refsource_CONFIRMThird Party Advisory
- https://github.com/torvalds/linux/commit/f843ee6dd019bcece3e74e76ad9df0155655d0df x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-7184
- https://source.android.com/security/bulletin/2017-05-01 x_refsource_CONFIRMThird Party Advisory
- https://twitter.com/thezdi/status/842126074435665920 x_refsource_MISCPress/Media CoverageThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-7184
Change history (0)
No recorded changes yet.