CVE-2017-12146
published 2017-09-08CVE-2017-12146: The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race…
PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.30%
21.9th percentile
The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.11.11-1 (bookworm) | linux 4.11.11-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 3.17 < 3.18.61 | 3.18.61 |
| linux | linux_kernel | >= 3.19 < 4.1.43 | 4.1.43 |
| linux | linux_kernel | >= 4.10 < 4.11.10 | 4.11.10 |
| linux | linux_kernel | >= 4.12 < 4.12.1 | 4.12.1 |
| linux | linux_kernel | >= 4.2 < 4.4.77 | 4.4.77 |
| linux | linux_kernel | >= 4.5 < 4.9.37 | 4.9.37 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-12-07·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3508-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-12-07·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Yonggang Guo discovered that a race condition existed in the driver
subsystem in the Linux kernel. A local attacker could use this to possibly
gain administrative privileges. (CVE-2017-12146
Android
CVE-2017-12146: Linux kernel
vendor_android·2017-09-01·CVSS 7.0
CVE-2017-12146 [HIGH] CVE-2017-12146: Linux kernel
Android Security Bulletin 2017-09-01
CVE: CVE-2017-12146
Severity: MEDIUM
Type: EoP
Component: Linux kernel
References: A-35676417
Upstream kernel
Red Hat
kernel: Race condition in driver_override implementation
vendor_redhat·2017-05-25·CVSS 7.0
CVE-2017-12146 [HIGH] CWE-362 kernel: Race condition in driver_override implementation
kernel: Race condition in driver_override implementation
The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.
It was found that the driver_override implementation in base/platform.c in the Linux kernel is susceptible to race condition when different threads are reading vs storing a different driver override.
Statement: This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and MRG-2 as the code with the flaw is not present in the products listed.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise L
Debian
CVE-2017-12146: linux - The driver_override implementation in drivers/base/platform.c in the Linux kerne...
vendor_debian·2017·CVSS 7.0
CVE-2017-12146 [HIGH] CVE-2017-12146: linux - The driver_override implementation in drivers/base/platform.c in the Linux kerne...
The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.
Scope: local
bookworm: resolved (fixed in 4.11.11-1)
bullseye: resolved (fixed in 4.11.11-1)
forky: resolved (fixed in 4.11.11-1)
sid: resolved (fixed in 4.11.11-1)
trixie: resolved (fixed in 4.11.11-1)
GHSA
GHSA-6h2m-2j87-hjv5: The driver_override implementation in drivers/base/platform
ghsa_unreviewed·2022-05-13
CVE-2017-12146 [HIGH] CWE-362 GHSA-6h2m-2j87-hjv5: The driver_override implementation in drivers/base/platform
The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.
OSV
linux-hwe vulnerabilities
osv·2017-12-07·CVSS 7.0
CVE-2017-16939 [HIGH] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3508-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Yonggang Guo discovered that a race condition existed in the
OSV
CVE-2017-12146: The driver_override implementation in drivers/base/platform
osv·2017-09-08·CVSS 7.0
CVE-2017-12146 [HIGH] CVE-2017-12146: The driver_override implementation in drivers/base/platform
The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12146 kernel: Race condition in driver_override implementation
bugzilla·2017-09-06·CVSS 7.0
CVE-2017-12146 [HIGH] CVE-2017-12146 kernel: Race condition in driver_override implementation
CVE-2017-12146 kernel: Race condition in driver_override implementation
It was found that the driver_override implementation in base/platform.c is susceptible to race condition when different threads are reading vs storing a different driver override.
Upstream patch:
https://github.com/torvalds/linux/commit/6265539776a0810b7ce6398c27866ddb9c6bd154
Introduced by commit:
https://github.com/torvalds/linux/commit/3d713e0e382e
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1489079]
---
External References:
https://source.android.com/security/bulletin/2017-09-01
---
This was fixed in the 4.12.1 stable release and is on all currently supported Fedora releases.
---
Statement:
This issue does not affect the versions of the Linux kernel as shipped w
Bugzilla
CVE-2017-12146 kernel: Race condition in driver_override implementation [fedora-all]
bugzilla·2017-09-06·CVSS 7.0
CVE-2017-12146 [HIGH] CVE-2017-12146 kernel: Race condition in driver_override implementation [fedora-all]
CVE-2017-12146 kernel: Race condition in driver_override implementation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
arXiv
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
arxiv_fulltext·2024-03-30
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
A Context-Sensitive, Outlier-Based Static Analysis to Find Kernel Race Conditions
Niels Dossche
Ghent University
Bert Abrath
Ghent University
Bart Coppens
Ghent University
* [1][1ex]
-0.5ex 0.5ex 0 0
* [1][1ex]
-0.5ex 0.5ex 0 0
* [1][1ex]
0 0.5ex 0 0
* [1][1ex]
* [1][1ex]
* [1][1ex]
1mm
bccnt
[1]bccnt
magentaBart [ ]: #1
bacnt
[1]bacnt
blueBert [ ]: #1
ndcnt
carrotorangergb0.93, 0.57, 0.13
[1]ndcnt
carrotorangeNiels [ ]: #1
LLIF
[1]round(#1, 2) (floor(100*#1) == 100*#1) ? 0 : 9 0.00
[2]
#1#2
[1]100 * #1falsepositives / (#1truepositives + #1falsepositives)%
1214
24
23
1107
211
648
248
modulesandcorenoheuristics
611
257
169
185
modulesandcoreallheuristics
0.10%
1 minute and 3 seconds
56 seconds
49 seconds
8 minutes and 59 seconds
5 minutes and 42 seconds
mygreenrgb0,
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6265539776a0810b7ce6398c27866ddb9c6bd154http://www.debian.org/security/2017/dsa-3981http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.1http://www.securityfocus.com/bid/100651https://bugzilla.redhat.com/show_bug.cgi?id=1489078https://bugzilla.suse.com/show_bug.cgi?id=1057474https://github.com/torvalds/linux/commit/6265539776a0810b7ce6398c27866ddb9c6bd154https://source.android.com/security/bulletin/2017-09-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6265539776a0810b7ce6398c27866ddb9c6bd154http://www.debian.org/security/2017/dsa-3981http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.1http://www.securityfocus.com/bid/100651https://bugzilla.redhat.com/show_bug.cgi?id=1489078https://bugzilla.suse.com/show_bug.cgi?id=1057474https://github.com/torvalds/linux/commit/6265539776a0810b7ce6398c27866ddb9c6bd154https://source.android.com/security/bulletin/2017-09-01
2017-09-08
Published