Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15265

Опубликовано: 11 окт. 2017
Источник: redhat
CVSS3: 5.5

Описание

Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.

A use-after-free vulnerability was found when issuing an ioctl to a sound device. This could allow a user to exploit a race condition and create memory corruption or possibly privilege escalation.

Отчет

This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5,6, 7, realtime and MRG-2. Red Hat Enterprise Linux 5 has transitioned to Production phase 3.
During the Production 3 Phase, Critical impact Security Advisories (RHSAs) and selected Urgent Priority Bug Fix Advisories (RHBAs) may be released as they become available. The official life cycle policy can be reviewed here: http://redhat.com/rhel/lifecycle Future Linux kernel updates for the respective releases may address this issue.

Меры по смягчению последствий

It is possible to prevent the affected code from being loaded by blacklisting the kernel module snd_seq. Instructions relating to how to blacklist a kernel module are shown here: https://access.redhat.com/solutions/41278 Alternatively a custom permission set can be created by udev, the correct permissions will depend on your use case. Please contact Red Hat customer support for creating a rule set that can minimize flaw exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7kernel-altAffected
Red Hat Enterprise Linux 5.9 Long LifekernelFixedRHSA-2018:382313.12.2018
Red Hat Enterprise Linux 5 Extended Lifecycle SupportkernelFixedRHSA-2018:382213.12.2018
Red Hat Enterprise Linux 6kernelFixedRHSA-2018:239014.08.2018
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2018:067610.04.2018
Red Hat Enterprise Linux 7kernelFixedRHSA-2018:106210.04.2018
Red Hat Enterprise Linux 7.4 Extended Update SupportkernelFixedRHSA-2018:113017.04.2018
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2018:117017.04.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1501878kernel: Use-after-free in snd_seq_ioctl_create_port()

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
больше 7 лет назад

Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.

CVSS3: 7
nvd
больше 7 лет назад

Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.

CVSS3: 7
debian
больше 7 лет назад

Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 ...

CVSS3: 7
github
около 3 лет назад

Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.

suse-cvrf
больше 7 лет назад

Security update for the Linux Kernel

5.5 Medium

CVSS3