CVE-2017-10661
published 2017-08-19CVE-2017-10661: Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or…
PriorityP344high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EXPLOIT
EPSS
13.38%
96.0th percentile
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.9.30-1 (bookworm) | linux 4.9.30-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 3.2.92 | 3.2.92 |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
| linux | linux_kernel | >= 0 < 3.13.0-135.184 | 3.13.0-135.184 |
| linux | linux_kernel | >= 3.17 < 3.18.52 | 3.18.52 |
| linux | linux_kernel | >= 3.19 < 4.1.41 | 4.1.41 |
| linux | linux_kernel | >= 3.3 < 3.16.47 | 3.16.47 |
| linux | linux_kernel | >= 4.10 < 4.10.15 | 4.10.15 |
| linux | linux_kernel | >= 4.2 < 4.4.67 | 4.4.67 |
| linux | linux_kernel | >= 4.5 < 4.9.27 | 4.9.27 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gg87-xrj2-3r8m: Race condition in fs/timerfd
ghsa_unreviewed·2022-05-14
CVE-2017-10661 [HIGH] CWE-416 GHSA-gg87-xrj2-3r8m: Race condition in fs/timerfd
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
OSV
linux vulnerabilities
osv·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] linux vulnerabilities
linux vulnerabilities
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10661)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary co
OSV
CVE-2017-10661: Race condition in fs/timerfd
osv·2017-08-19·CVSS 7.0
CVE-2017-10661 [HIGH] CVE-2017-10661: Race condition in fs/timerfd
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10661)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use t
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3470-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash
Android
CVE-2017-10661: File system
vendor_android·2017-08-01·CVSS 7.0
CVE-2017-10661 [HIGH] CVE-2017-10661: File system
Android Security Bulletin 2017-08-01
CVE: CVE-2017-10661
Severity: HIGH
Type: EoP
Component: File system
References: A-36266767
Upstream
kernel
Red Hat
kernel: Handling of might_cancel queueing is not properly pretected against race
vendor_redhat·2017-02-10·CVSS 7.0
CVE-2017-10661 [HIGH] CWE-362 kernel: Handling of might_cancel queueing is not properly pretected against race
kernel: Handling of might_cancel queueing is not properly pretected against race
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
A race condition was found in the Linux kernel before version 4.11-rc1 in 'fs/timerfd.c' file which allows a local user to cause a kernel list corruption or use-after-free via simultaneous operations with a file descriptor which leverage improper 'might_cancel' queuing. An unprivileged local user could use this flaw to cause a denial of service of the system. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we belie
Debian
CVE-2017-10661: linux - Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local u...
vendor_debian·2017·CVSS 7.0
CVE-2017-10661 [HIGH] CVE-2017-10661: linux - Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local u...
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
Scope: local
bookworm: resolved (fixed in 4.9.30-1)
bullseye: resolved (fixed in 4.9.30-1)
forky: resolved (fixed in 4.9.30-1)
sid: resolved (fixed in 4.9.30-1)
trixie: resolved (fixed in 4.9.30-1)
No detection rules found.
arXiv
Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation
arxiv_fulltext·2024-11-09
Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation
empty
### Abstract
Recently, a novel method known as Page Spray emerges, focusing on page-level exploitation for kernel vulnerabilities. Despite the advantages it offers in terms of exploitability, stability, and compatibility, comprehensive research on Page Spray remains scarce. Questions regarding its root causes, exploitation model, comparative benefits over other exploitation techniques, and possible mitigation strategies have largely remained unanswered. In this paper, we conduct a systematic investigation into Page Spray, providing an in-depth understanding of this exploitation technique. We introduce a comprehensive exploit model termed the model, elucidating its fundamental principles. Additionally, we conduct a thorough analysis of the root causes underlying Page Spray occurrenc
arXiv
Understanding Concurrency Vulnerabilities in Linux Kernel
arxiv_fulltext·2022-12-11
Understanding Concurrency Vulnerabilities in Linux Kernel
Understanding Concurrency Vulnerabilities in Linux Kernel
Zunchen Huang
University of Southern California
Los Angeles, CA
USA
Shengjian Guo
Baidu Security
Sunnyvale, CA
USA
Meng Wu
Virginia Tech
Blacksburg, VA
USA
Chao Wang
University of Southern California
Los Angeles, CA
USA
## Abstract
While there is a large body of work on analyzing concurrency related
software bugs and developing techniques for detecting and patching
them, little attention has been given to concurrency related security
vulnerabilities. The two are different in that not all bugs are
vulnerabilities: for a bug to be exploitable, there needs be a way for
attackers to trigger its execution and cause damage, e.g., by
revealing sensitive data or running malicious code.
To fill the gap, we conduct the first empiri
Bugzilla
CVE-2017-10661 kernel: Handling of might_cancel queueing is not properly pretected against race
bugzilla·2017-08-14·CVSS 7.0
CVE-2017-10661 [HIGH] CVE-2017-10661 kernel: Handling of might_cancel queueing is not properly pretected against race
CVE-2017-10661 kernel: Handling of might_cancel queueing is not properly pretected against race
The handling of the might_cancel queueing is not properly protected, so parallel operations on the file descriptor can race with each other and lead to list corruptions or use after free.
References:
https://marc.info/?l=linux-fsdevel&m=148587265720603&w=2
https://marc.info/?t=148587273100007&r=1&w=2
https://source.android.com/security/bulletin/2017-08-01#kernel-components
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1e38da300e1e395a15048b0af1e5305bd91402f6
Discussion:
Statement:
This issue does not affect Red Hat Enterprise Linux 5 as the code with the flaw is not present in the products listed.
This issue affects Red Hat Enterprise Li
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e38da300e1e395a15048b0af1e5305bd91402f6http://www.debian.org/security/2017/dsa-3981http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.15http://www.securityfocus.com/bid/100215https://access.redhat.com/errata/RHSA-2018:3083https://access.redhat.com/errata/RHSA-2018:3096https://access.redhat.com/errata/RHSA-2019:4057https://access.redhat.com/errata/RHSA-2019:4058https://access.redhat.com/errata/RHSA-2020:0036https://bugzilla.redhat.com/show_bug.cgi?id=1481136https://github.com/torvalds/linux/commit/1e38da300e1e395a15048b0af1e5305bd91402f6https://source.android.com/security/bulletin/2017-08-01https://www.exploit-db.com/exploits/43345/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e38da300e1e395a15048b0af1e5305bd91402f6http://www.debian.org/security/2017/dsa-3981http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.15http://www.securityfocus.com/bid/100215https://access.redhat.com/errata/RHSA-2018:3083https://access.redhat.com/errata/RHSA-2018:3096https://access.redhat.com/errata/RHSA-2019:4057https://access.redhat.com/errata/RHSA-2019:4058https://access.redhat.com/errata/RHSA-2020:0036https://bugzilla.redhat.com/show_bug.cgi?id=1481136https://github.com/torvalds/linux/commit/1e38da300e1e395a15048b0af1e5305bd91402f6https://source.android.com/security/bulletin/2017-08-01https://www.exploit-db.com/exploits/43345/
2017-08-19
Published