kernel: net/packet: overflow in check for priv area size
Published Mar 29, 2017
7.8
HIGHCVSS 3.1
EPSS 17.83%
Description
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
Affected products
No data.
- ≥ 2.6.27 · < 3.2.89
- ≥ 3.3 · < 3.10.107
- ≥ 3.11 · < 3.12.74
- ≥ 3.13 · < 3.16.44
- ≥ 3.17 · < 3.18.52
- ≥ 3.19 · < 4.1.41
- ≥ 4.2 · < 4.4.66
- ≥ 4.5 · < 4.9.26
- ≥ 4.10 · < 4.10.14
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.el6
Fixed · RHSA-2018:1854
Red Hat Enterprise Linux 7
kernel-0:3.10.0-514.21.1.el7
Fixed · RHSA-2017:1308
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-514.21.1.rt56.438.el7
Fixed · RHSA-2017:1298
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-514.rt56.221.el6rt
Fixed · RHSA-2017:1297
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.el6 | Fixed | RHSA-2018:1854 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-514.21.1.el7 | Fixed | RHSA-2017:1308 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-514.21.1.rt56.438.el7 | Fixed | RHSA-2017:1298 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-514.rt56.221.el6rt | Fixed | RHSA-2017:1297 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect Red Hat Enterprise Linux 5. In a default or common use of Red Hat Enterprise Linux 6 and 7 this issue does not allow an unprivileged local user elevate their privileges on the system. In order to exploit this issue the attacker needs CAP_NET_RAW capability, which needs to be granted by the administrator to the attacker's account. Since Red Hat Enterprise Linux 6 does not have namespaces support and Red Hat Enterprise Linux 7 does not have unprivileged user namespaces enabled by default, local unprivileged users also cannot abuse namespaces feature to grant this capability to themselves and elevate their privileges. So, this issue does not affect Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2 in the default configuration. Future updates for the respective releases will address this issue to secure non-default configurations. In the non-default configuration mentioned above only Red Hat Enterprise Linux 7 is vulnerable to a privilege escalation. Red Hat Enterprise Linux 6 is vulnerable only to a denial of service (DoS) due to a system crash, hence the impact on Red Hat Enterprise Linux 6 is rated as being Moderate.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (44 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 17.83% (0.17827) | 97.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 17.83% (0.17827) | 96.78th | v5 (v2026.06.15) |
| Mar 4, 2026 | 86.47% (0.86465) | 99.40th | v4 (v2025.03.14) |
| Mar 1, 2026 | 83.25% (0.83248) | 99.25th | v4 (v2025.03.14) |
| Feb 4, 2026 | 86.28% (0.86279) | 99.39th | v4 (v2025.03.14) |
| Feb 1, 2026 | 82.99% (0.82990) | 99.24th | v4 (v2025.03.14) |
| Jan 4, 2026 | 86.12% (0.86119) | 99.37th | v4 (v2025.03.14) |
| Jan 1, 2026 | 82.77% (0.82768) | 99.22th | v4 (v2025.03.14) |
| Dec 4, 2025 | 86.79% (0.86794) | 99.38th | v4 (v2025.03.14) |
| Dec 1, 2025 | 82.34% (0.82336) | 99.19th | v4 (v2025.03.14) |
| Nov 21, 2025 | 87.54% (0.87544) | 99.42th | v4 (v2025.03.14) |
| Nov 18, 2025 | 89.59% (0.89591) | 99.65th | v4 (v2025.03.14) |
| Nov 4, 2025 | 87.54% (0.87544) | 99.42th | v4 (v2025.03.14) |
| Nov 1, 2025 | 83.51% (0.83506) | 99.24th | v4 (v2025.03.14) |
| Oct 4, 2025 | 86.93% (0.86934) | 99.40th | v4 (v2025.03.14) |
| Oct 1, 2025 | 83.90% (0.83898) | 99.27th | v4 (v2025.03.14) |
| Sep 4, 2025 | 87.36% (0.87362) | 99.42th | v4 (v2025.03.14) |
| Sep 1, 2025 | 83.22% (0.83222) | 99.23th | v4 (v2025.03.14) |
| Aug 7, 2025 | 87.02% (0.87018) | 99.40th | v4 (v2025.03.14) |
| Aug 1, 2025 | 82.91% (0.82908) | 99.21th | v4 (v2025.03.14) |
| Jul 4, 2025 | 86.66% (0.86659) | 99.37th | v4 (v2025.03.14) |
| Jul 1, 2025 | 82.13% (0.82127) | 99.16th | v4 (v2025.03.14) |
| Jun 4, 2025 | 86.70% (0.86696) | 99.37th | v4 (v2025.03.14) |
| Jun 1, 2025 | 81.87% (0.81873) | 99.15th | v4 (v2025.03.14) |
| May 11, 2025 | 86.29% (0.86294) | 99.34th | v4 (v2025.03.14) |
| May 1, 2025 | 81.23% (0.81234) | 99.10th | v4 (v2025.03.14) |
| Apr 19, 2025 | 86.29% (0.86294) | 99.33th | v4 (v2025.03.14) |
| Apr 18, 2025 | 81.23% (0.81234) | 99.09th | v4 (v2025.03.14) |
| Apr 14, 2025 | 86.29% (0.86294) | 99.37th | v4 (v2025.03.14) |
| Apr 13, 2025 | 81.23% (0.81234) | 99.13th | v4 (v2025.03.14) |
| Mar 20, 2025 | 86.26% (0.86255) | 99.39th | v4 (v2025.03.14) |
| Mar 19, 2025 | 83.84% (0.83839) | 99.25th | v4 (v2025.03.14) |
| Mar 17, 2025 | 86.26% (0.86255) | 99.36th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.09% (0.00088) | 39.38th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00089) | 36.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.20% (0.02195) | 81.07th | v2 (v2022.01.01) |
| Jan 10, 2023 | 2.20% (0.02195) | 80.43th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.21% (0.02212) | 79.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.21% (0.02212) | 58.06th | v2 (v2022.01.01) |
| Feb 3, 2022 | 37.65% (0.37648) | 98.11th | v1 |
| Sep 16, 2021 | 37.65% (0.37648) | 99.17th | v1 |
| Sep 14, 2021 | 7.55% (0.07554) | 91.53th | v1 |
| Sep 1, 2021 | 37.65% (0.37648) | 99.17th | v1 |
| Apr 14, 2021 | 37.65% (0.37648) | 0.00th | v1 |
References (16)
- http://www.securityfocus.com/bid/97234 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1297 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1298 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1308 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1854 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-7308 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1437404 Issue Tracking
- https://googleprojectzero.blogspot.com/2017/05/exploiting-linux-kernel-via-packet.html x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-7308
- https://patchwork.ozlabs.org/patch/744811/ x_refsource_CONFIRMThird Party Advisory
- https://patchwork.ozlabs.org/patch/744812/ x_refsource_CONFIRMThird Party Advisory
- https://patchwork.ozlabs.org/patch/744813/ x_refsource_CONFIRMThird Party Advisory
- https://source.android.com/security/bulletin/2017-07-01 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-7308
- https://www.exploit-db.com/exploits/41994/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44654/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.