cbcvebase.
CVE-2017-11600
published 2017-07-24

CVE-2017-11600: net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is…

PriorityP427high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.41%
33.4th percentile
net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via an XFRM_MSG_MIGRATE xfrm Netlink message.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 4.12.6-1 (bookworm)linux 4.12.6-1 (bookworm)
linuxlinux_kernel>= 0 < 4.12.6-14.12.6-1
linuxlinux_kernel>= 0 < 4.12.6-14.12.6-1
linuxlinux_kernel>= 0 < 4.12.6-14.12.6-1
linuxlinux_kernel>= 0 < 4.12.6-14.12.6-1
linuxlinux_kernel>= 2.6.21 < 3.2.933.2.93
linuxlinux_kernel>= 3.11 < 3.18.703.18.70
linuxlinux_kernel>= 3.19 < 4.1.454.1.45
linuxlinux_kernel>= 3.3 < 3.10.1083.10.108
linuxlinux_kernel>= 4.10 < 4.12.114.12.11
linuxlinux_kernel>= 4.2 < 4.4.874.4.87
linuxlinux_kernel>= 4.5 < 4.9.484.9.48

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.