CVE-2017-0386
published 2017-01-12CVE-2017-0386: An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a…
PriorityP336high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.16%
63.8th percentile
An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnl3 | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0386: Android Security Bulletin 2017-01-01
CVE: CVE-2017-0386
Severity: HIGH
Affected AOSP versions: 5
vendor_android·2017-01-01·CVSS 7.8
CVE-2017-0386 [HIGH] CVE-2017-0386: Android Security Bulletin 2017-01-01
CVE: CVE-2017-0386
Severity: HIGH
Affected AOSP versions: 5
Android Security Bulletin 2017-01-01
CVE: CVE-2017-0386
Severity: HIGH
Affected AOSP versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1
References: A-32255299
Debian
CVE-2017-0386: libnl3 - An elevation of privilege vulnerability in the libnl library could enable a loca...
vendor_debian·2017·CVSS 7.8
CVE-2017-0386 [HIGH] CVE-2017-0386: libnl3 - An elevation of privilege vulnerability in the libnl library could enable a loca...
An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put
vendor_redhat·2016-12-01·CVSS 7.8
CVE-2017-0386 [HIGH] CWE-190 libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put
libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put
An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.
Package: libnl (Red Hat Enterprise Linux 5) - Not affected
Package: libnl (Red Hat Enterprise Linux 6) - Not affected
Package: libnl3 (Red Hat Enterprise Linux 6) - Not affected
Package: libnl (Red Hat Enterprise Linux 7) - Not affected
Package: libnl3 (Red Hat Enterprise Linux 7)
GHSA
GHSA-h6x2-f4w7-459j: An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context o
ghsa_unreviewed·2022-05-13
CVE-2017-0386 [HIGH] GHSA-h6x2-f4w7-459j: An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context o
An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-0386 libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put
bugzilla·2017-01-18·CVSS 7.8
CVE-2017-0386 [HIGH] CVE-2017-0386 libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put
CVE-2017-0386 libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put
An elevation of privilege vulnerability in the libnl library could enable a
local malicious application to execute arbitrary code within the context of a
privileged process.
References:
https://android.googlesource.com/platform/external/libnl/+/f0b40192efd1af977564ed6335d42a8bbdaf650a
https://github.com/thom311/libnl/issues/124
Discussion:
Created libnl3 tracking bugs for this issue:
Affects: fedora-all [bug 1414305]
---
This CVE seems to be specific to Android's usage of (its fork of) libnl, allowing calls into libnl to cross process (and therefore privilege) boundaries.
On Fedora and Enterprise Linux, libnl inherits the privilege domain of the process which opens it (through dyna
Bugzilla
CVE-2017-0386 libnl3: libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put [fedora-all]
bugzilla·2017-01-18·CVSS 7.8
CVE-2017-0386 [HIGH] CVE-2017-0386 libnl3: libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put [fedora-all]
CVE-2017-0386 libnl3: libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
2017-01-12
Published