Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-8824

Опубликовано: 05 дек. 2017
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.

A use-after-free vulnerability was found in DCCP socket code affecting the Linux kernel since 2.6.16. This vulnerability could allow an attacker to their escalate privileges.

Отчет

This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7, Red Hat Enterprise MRG 2 and real-time kernels. Future updates for the respective releases may address this issue. This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 for ARM and Red Hat Enterprise Linux 7 for Power LE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 5 Extended Lifecycle SupportkernelFixedRHSA-2018:382213.12.2018
Red Hat Enterprise Linux 6kernelFixedRHSA-2018:131908.05.2018
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2018:067610.04.2018
Red Hat Enterprise Linux 7kernelFixedRHSA-2018:106210.04.2018
Red Hat Enterprise Linux 7.2 Advanced Update SupportkernelFixedRHSA-2018:121624.04.2018
Red Hat Enterprise Linux 7.2 Telco Extended Update SupportkernelFixedRHSA-2018:121624.04.2018
Red Hat Enterprise Linux 7.2 Update Services for SAP SolutionskernelFixedRHSA-2018:121624.04.2018
Red Hat Enterprise Linux 7.3 Extended Update SupportkernelFixedRHSA-2018:039906.03.2018
Red Hat Enterprise Linux 7.4 Extended Update SupportkernelFixedRHSA-2018:113017.04.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1519591kernel: Use-after-free vulnerability in DCCP socket

EPSS

Процентиль: 72%
0.00726
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.

CVSS3: 7.8
nvd
больше 7 лет назад

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.

CVSS3: 7.8
debian
больше 7 лет назад

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel t ...

CVSS3: 7.8
github
около 3 лет назад

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость функции dccp_disconnect (net/dccp/proto.c) ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 72%
0.00726
Низкий

7.8 High

CVSS3