Логотип exploitDog
bind:"GHSA-9324-w9gg-mxf6" OR bind:"CVE-2017-15129"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-9324-w9gg-mxf6" OR bind:"CVE-2017-15129"

Количество 12

Количество 12

github логотип

GHSA-9324-w9gg-mxf6

около 3 лет назад

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-15129

больше 7 лет назад

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2017-15129

больше 7 лет назад

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-15129

больше 7 лет назад

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2017-15129

больше 7 лет назад

A use-after-free vulnerability was found in network namespaces code af ...

CVSS3: 4.7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0408-1

больше 7 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:0482-1

больше 7 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:0416-1

больше 7 лет назад

Security update for the Linux Kernel

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:0383-1

больше 7 лет назад

Security update for the Linux Kernel

EPSS: Низкий
oracle-oval логотип

ELSA-2018-4108

около 7 лет назад

ELSA-2018-4108: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:0986-1

около 7 лет назад

Security update for the Linux Kernel

EPSS: Низкий
oracle-oval логотип

ELSA-2018-1062

около 7 лет назад

ELSA-2018-1062: kernel security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9324-w9gg-mxf6

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2017-15129

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 4.7
0%
Низкий
больше 7 лет назад
redhat логотип
CVE-2017-15129

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-15129

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS3: 4.7
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-15129

A use-after-free vulnerability was found in network namespaces code af ...

CVSS3: 4.7
0%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0408-1

Security update for the Linux Kernel

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:0482-1

Security update for the Linux Kernel

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:0416-1

Security update for the Linux Kernel

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:0383-1

Security update for the Linux Kernel

больше 7 лет назад
oracle-oval логотип
ELSA-2018-4108

ELSA-2018-4108: Unbreakable Enterprise kernel security update (IMPORTANT)

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:0986-1

Security update for the Linux Kernel

около 7 лет назад
oracle-oval логотип
ELSA-2018-1062

ELSA-2018-1062: kernel security, bug fix, and enhancement update (IMPORTANT)

около 7 лет назад

Уязвимостей на страницу