CVE-2017-10663
published 2017-08-19CVE-2017-10663: The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.44%
35.9th percentile
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.12.6-1 (bookworm) | linux 4.12.6-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 3.13.0-135.184 | 3.13.0-135.184 |
| linux | linux_kernel | >= 0 < 4.4.0-96.119 | 4.4.0-96.119 |
| linux | linux_kernel | >= 3.19 < 4.1.44 | 4.1.44 |
| linux | linux_kernel | >= 3.8 < 3.18.64 | 3.18.64 |
| linux | linux_kernel | >= 4.10 < 4.12.4 | 4.12.4 |
| linux | linux_kernel | >= 4.2 < 4.4.81 | 4.4.81 |
| linux | linux_kernel | >= 4.5 < 4.9.42 | 4.9.42 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.0HIGH
vendor_ubuntu8.0HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3468-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
in
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10661)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use t
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3470-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 8.0
CVE-2017-1000251 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
It was discovered that a buffer overflow existed in the ioctl handling code
in the ISDN subsystem of the Linux kernel. A local attacker could use this
to cause a denial of ser
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-09-18·CVSS 8.0
CVE-2017-1000251 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3420-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
Android
CVE-2017-10663: File System
vendor_android·2017-08-01·CVSS 7.8
CVE-2017-10663 [HIGH] CVE-2017-10663: File System
Android Security Bulletin 2017-08-01
CVE: CVE-2017-10663
Severity: MEDIUM
Type: EoP
Component: File System
References: A-36588520
Upstream
kernel
Red Hat
kernel: Missing sanity check for segno and blkoff read
vendor_redhat·2017-05-12·CVSS 7.8
CVE-2017-10663 [HIGH] CWE-391 kernel: Missing sanity check for segno and blkoff read
kernel: Missing sanity check for segno and blkoff read
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before version 4.12.4 does not validate the blkoff and segno arrays. This allows an unprivileged, local user to cause a system panic and DoS. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
Statement: This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 as the code with the flaw is not built and shipped with the produc
Debian
CVE-2017-10663: linux - The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.1...
vendor_debian·2017·CVSS 7.8
CVE-2017-10663 [HIGH] CVE-2017-10663: linux - The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.1...
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.6-1)
forky: resolved (fixed in 4.12.6-1)
sid: resolved (fixed in 4.12.6-1)
trixie: resolved (fixed in 4.12.6-1)
GHSA
GHSA-596f-c2w8-w394: The sanity_check_ckpt function in fs/f2fs/super
ghsa_unreviewed·2022-05-17
CVE-2017-10663 [HIGH] CWE-129 GHSA-596f-c2w8-w394: The sanity_check_ckpt function in fs/f2fs/super
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
OSV
linux vulnerabilities
osv·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] linux vulnerabilities
linux vulnerabilities
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10661)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary co
OSV
linux-gcp vulnerabilities
osv·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] linux-gcp vulnerabilities
linux-gcp vulnerabilities
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2017-10911)
It was disc
OSV
linux-hwe vulnerabilities
osv·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3468-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initi
OSV
linux-lts-xenial vulnerabilities
osv·2017-09-18·CVSS 8.0
CVE-2017-1000251 [HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3420-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
It was discovered that a buffe
OSV
linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-09-18·CVSS 8.0
CVE-2017-1000251 [HIGH] linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a buffer overflow existed in the Bluetooth stack of
the Linux kernel when handling L2CAP configuration responses. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2017-1000251)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
It was discovered that a buffer overflow existed in the ioctl handling code
in the ISDN subsystem of the Linux kernel. A local attacker could use this
to cause a denial of service (system cr
OSV
CVE-2017-10663: The sanity_check_ckpt function in fs/f2fs/super
osv·2017-08-19·CVSS 7.8
CVE-2017-10663 [HIGH] CVE-2017-10663: The sanity_check_ckpt function in fs/f2fs/super
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10663 kernel: Missing sanity check for segno and blkoff read [fedora-all]
bugzilla·2017-08-14·CVSS 7.8
CVE-2017-10663 [HIGH] CVE-2017-10663 kernel: Missing sanity check for segno and blkoff read [fedora-all]
CVE-2017-10663 kernel: Missing sanity check for segno and blkoff read [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2017-10663 kernel: Missing sanity check for segno and blkoff read
bugzilla·2017-08-14·CVSS 7.8
CVE-2017-10663 [HIGH] CVE-2017-10663 kernel: Missing sanity check for segno and blkoff read
CVE-2017-10663 kernel: Missing sanity check for segno and blkoff read
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows an unprivileged local user to cause a system panic and DoS. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://source.android.com/security/bulletin/2017-08-01#kernel-components
https://sourceforge.net/p/linux-f2fs/mailman/message/35835945/
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=15d3042a937c13f5d9244241c7a9c8416ff6e82a
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1481153]
---
Statement:
This issu
Trendmicro
Vulnerability in F2FS Leads To Memory Corruption
blogs_trendmicro·2017-08-08·CVSS 7.8
CVE-2017-10663 [HIGH] Vulnerability in F2FS Leads To Memory Corruption
## Vulnerability in F2FS Leads To Memory Corruption
A malicious app could be used to trigger this vulnerability, which occurs when a malicious disk using the F2FS (Flash-Friendly File System) is mounted. The disk can either be an actual physical device or a virtual file image
By: Veo Zhang Aug 08, 2017 Read time: ( words)
Save to Folio
August’s Android Security Bulletin includes three file system vulnerabilities ( CVE-2017-10663 , CVE-2017-10662 , and CVE-2017-0750 ) that were discovered by Trend Micro researchers. These vulnerabilities could cause memory corruption on the affected devices, leading to code execution in the kernel context. This would allow for more data to be accessed and controlled by the malware. A malicious app could be used to trigger this vulnerability, which occur
Trendmicro
Vulnerability in F2FS Leads To Memory Corruption
blogs_trendmicro·2017-08-08·CVSS 7.8
CVE-2017-10663 [HIGH] Vulnerability in F2FS Leads To Memory Corruption
## Vulnerability in F2FS Leads To Memory Corruption
A malicious app could be used to trigger this vulnerability, which occurs when a malicious disk using the F2FS (Flash-Friendly File System) is mounted. The disk can either be an actual physical device or a virtual file image
By: Veo Zhang Aug 08, 2017 Read time: ( words)
Save to Folio
August’s Android Security Bulletin includes three file system vulnerabilities ( CVE-2017-10663 , CVE-2017-10662 , and CVE-2017-0750 ) that were discovered by Trend Micro researchers. These vulnerabilities could cause memory corruption on the affected devices, leading to code execution in the kernel context. This would allow for more data to be accessed and controlled by the malware. A malicious app could be used to trigger this vulnerability, which occur
Trendmicro
Vulnerability in F2FS Leads To Memory Corruption
blogs_trendmicro·2017-08-08·CVSS 7.8
CVE-2017-10663 [HIGH] Vulnerability in F2FS Leads To Memory Corruption
# Vulnerability in F2FS Leads To Memory Corruption
A malicious app could be used to trigger this vulnerability, which occurs when a malicious disk using the F2FS (Flash-Friendly File System) is mounted. The disk can either be an actual physical device or a virtual file image
By: Veo Zhang
2017/08/08
Read time: ( words)
Save to Folio
August’s Android Security Bulletin includes three file system vulnerabilities (CVE-2017-10663, CVE-2017-10662, and CVE-2017-0750) that were discovered by Trend Micro researchers. These vulnerabilities could cause memory corruption on the affected devices, leading to code execution in the kernel context. This would allow for more data to be accessed and controlled by the malware. A malicious app could be used to trigger this vulnerability, which occurs when
Trendmicro
Vulnerability in F2FS Leads To Memory Corruption
blogs_trendmicro·2017-08-08·CVSS 7.8
CVE-2017-10663 [HIGH] Vulnerability in F2FS Leads To Memory Corruption
## Vulnerability in F2FS Leads To Memory Corruption
A malicious app could be used to trigger this vulnerability, which occurs when a malicious disk using the F2FS (Flash-Friendly File System) is mounted. The disk can either be an actual physical device or a virtual file image
By: Veo Zhang 2017/08/08 Read time: ( words)
Save to Folio
August’s Android Security Bulletin includes three file system vulnerabilities ( CVE-2017-10663 , CVE-2017-10662 , and CVE-2017-0750 ) that were discovered by Trend Micro researchers. These vulnerabilities could cause memory corruption on the affected devices, leading to code execution in the kernel context. This would allow for more data to be accessed and controlled by the malware. A malicious app could be used to trigger this vulnerability, which occurs
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15d3042a937c13f5d9244241c7a9c8416ff6e82ahttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.4http://www.securityfocus.com/bid/100215https://bugzilla.redhat.com/show_bug.cgi?id=1481149https://github.com/torvalds/linux/commit/15d3042a937c13f5d9244241c7a9c8416ff6e82ahttps://source.android.com/security/bulletin/2017-08-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15d3042a937c13f5d9244241c7a9c8416ff6e82ahttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.4http://www.securityfocus.com/bid/100215https://bugzilla.redhat.com/show_bug.cgi?id=1481149https://github.com/torvalds/linux/commit/15d3042a937c13f5d9244241c7a9c8416ff6e82ahttps://source.android.com/security/bulletin/2017-08-01
2017-08-19
Published