Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7895

Опубликовано: 28 апр. 2017
Источник: redhat
CVSS3: 6.5

Описание

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lacked certain checks for the end of a buffer. A remote attacker could trigger a pointer-arithmetic error or possibly cause other unspecified impacts using crafted requests related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

Отчет

This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 7.2kernel-rtAffected
Red Hat Enterprise Linux 5.9 Long LifekernelFixedRHSA-2017:247215.08.2017
Red Hat Enterprise Linux 5 Extended Lifecycle SupportkernelFixedRHSA-2017:241202.08.2017
Red Hat Enterprise Linux 6kernelFixedRHSA-2017:172311.07.2017
Red Hat Enterprise Linux 6.2 Advanced Update SupportkernelFixedRHSA-2017:273214.09.2017
Red Hat Enterprise Linux 6.4 Advanced Update SupportkernelFixedRHSA-2017:171511.07.2017
Red Hat Enterprise Linux 6.5 Advanced Update SupportkernelFixedRHSA-2017:242808.08.2017
Red Hat Enterprise Linux 6.5 Telco Extended Update SupportkernelFixedRHSA-2017:242808.08.2017
Red Hat Enterprise Linux 6.6 Advanced Update SupportkernelFixedRHSA-2017:179824.07.2017
Red Hat Enterprise Linux 6.6 Telco Extended Update SupportkernelFixedRHSA-2017:179824.07.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1446103kernel: NFSv3 server does not properly handle payload bounds checking of WRITE requests

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

CVSS3: 9.8
nvd
около 8 лет назад

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

CVSS3: 9.8
debian
около 8 лет назад

The NFSv2 and NFSv3 server implementations in the Linux kernel through ...

CVSS3: 9.8
github
около 3 лет назад

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

oracle-oval
около 8 лет назад

ELSA-2017-3565: Unbreakable Enterprise kernel security update (IMPORTANT)

6.5 Medium

CVSS3