Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10661

Опубликовано: 10 фев. 2017
Источник: redhat
CVSS3: 5.3
EPSS Средний

Описание

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

A race condition was found in the Linux kernel before version 4.11-rc1 in 'fs/timerfd.c' file which allows a local user to cause a kernel list corruption or use-after-free via simultaneous operations with a file descriptor which leverage improper 'might_cancel' queuing. An unprivileged local user could use this flaw to cause a denial of service of the system. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.

Отчет

This issue does not affect Red Hat Enterprise Linux 5 as the code with the flaw is not present in the products listed. This issue affects Red Hat Enterprise Linux 6 and 7. Future updates for the respective releases may address this issue. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux MRG-2. This flaw is not currently planned to be addressed in future updates due to MRG-2 being an EUS release. For additional information, refer to the Extended Update Support (EUS) Guide: https://access.redhat.com/articles/rhel-eus.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise MRG 2realtime-kernelWill not fix
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2018:309630.10.2018
Red Hat Enterprise Linux 7kernelFixedRHSA-2018:308330.10.2018
Red Hat Enterprise Linux 7.4 Advanced Update SupportkernelFixedRHSA-2019:405803.12.2019
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportkernelFixedRHSA-2019:405803.12.2019
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionskernelFixedRHSA-2019:405803.12.2019
Red Hat Enterprise Linux 7.5 Extended Update SupportkernelFixedRHSA-2020:003607.01.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1481136kernel: Handling of might_cancel queueing is not properly pretected against race

EPSS

Процентиль: 96%
0.27639
Средний

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
почти 8 лет назад

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

CVSS3: 7
nvd
почти 8 лет назад

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

CVSS3: 7
debian
почти 8 лет назад

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allo ...

CVSS3: 7
github
около 3 лет назад

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

CVSS3: 7
fstec
больше 8 лет назад

Уязвимость компонента timerfd.c ядра (fs/timerfd.c) операционной системы Linux, позволяющая нарушителю повысить свои привилегии и вызвать отказ в обслуживании

EPSS

Процентиль: 96%
0.27639
Средний

5.3 Medium

CVSS3