Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17523

Опубликовано: 18 авг. 2019
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

Отчет

This is an Important flaw in the Linux kernel's CAN BCM module that allows a local unprivileged attacker to achieve root privileges through arbitrary kernel code execution. The vulnerability is present in Red Hat Enterprise Linux 8, where a proof of concept has demonstrated local privilege escalation, even without unprivileged user namespaces or the kernel-modules-extra package.

Меры по смягчению последствий

To mitigate this vulnerability, prevent the bcm kernel module from loading if it is not required. Create a file named /etc/modprobe.d/blacklist-bcm.conf with the content blacklist bcm. A system reboot is required for this change to take effect. This mitigation may impact functionality that relies on the CAN BCM module.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelAffected
Red Hat Enterprise Linux 8kernel-rtAffected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2507407kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
21 день назад

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

CVSS3: 7.8
nvd
21 день назад

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

CVSS3: 7.8
debian
21 день назад

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, whe ...

CVSS3: 7.8
github
21 день назад

A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

7.8 High

CVSS3