[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80130

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2017-2671

Date: (C)2017-04-06   (M)2018-01-05 


The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.

CVSS Score: 4.9Access Vector: LOCAL
Exploit Score: 3.9Access Complexity: LOW
Impact Score: 6.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: COMPLETE





Reference:
EXPLOIT-DB-42135
BID-97407
RHSA-2017:1842
RHSA-2017:2077
RHSA-2017:2669
http://openwall.com/lists/oss-security/2017/04/04/8
https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/net/ipv4/ping.c?id=43a6684519ab0a6c52024b5e25322476cabad893
https://github.com/danieljiang0415/android_kernel_crash_poc
https://github.com/torvalds/linux/commit/43a6684519ab0a6c52024b5e25322476cabad893
https://twitter.com/danieljiang0415/status/845116665184497664

CWE    1
CWE-284
OVAL    10
oval:org.secpod.oval:def:112258
oval:org.secpod.oval:def:112262
oval:org.secpod.oval:def:1600698
oval:org.secpod.oval:def:1502082
...

© 2013 SecPod Technologies