Linux Kernel CVE-2017-16996 Local Memory Corruption Vulnerability
BID:102267
Info
Linux Kernel CVE-2017-16996 Local Memory Corruption Vulnerability
| Bugtraq ID: | 102267 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2017-16996 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 22 2017 12:00AM |
| Updated: | Dec 22 2017 12:00AM |
| Credit: | The vendor has reported this issue. |
| Vulnerable: |
Linux kernel 4.14.6 Linux kernel 4.14.5 Linux kernel 4.14.8 Linux kernel 4.14.7 Linux kernel 4.14.4 Linux kernel 4.14.3 Linux kernel 4.14.2 Linux kernel 4.14 |
| Not Vulnerable: | |
Discussion
Linux Kernel CVE-2017-16996 Local Memory Corruption Vulnerability
Linux Kernel is prone to a local memory-corruption vulnerability.
Attackers may be able to exploit this issue to execute arbitrary code with elevated privileges. Failed attack attempts will likely result in denial-of-service conditions.
Linux Kernel 4.14 through 4.14.8 are vulnerable.
Linux Kernel is prone to a local memory-corruption vulnerability.
Attackers may be able to exploit this issue to execute arbitrary code with elevated privileges. Failed attack attempts will likely result in denial-of-service conditions.
Linux Kernel 4.14 through 4.14.8 are vulnerable.
Exploit / POC
Linux Kernel CVE-2017-16996 Local Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel CVE-2017-16996 Local Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Linux Kernel CVE-2017-16996 Local Memory Corruption Vulnerability
References:
References:
- Linux kernel Homepage (kernel.org)
- fix incorrect tracking of register size truncation (kernel)
- bpf: fix incorrect tracking of register size truncation (github)
- CVE-2017-16996 kernel: memory corruption caused (redhat)
- CVE-2017-16996kernel: memory corruption caused by BPF verifier bugs (redhat)
- eBPF memory corruption bugs (openwall)
- eBPF memory corruption bugs (seclists)