CVE-2017-12193
published 2017-11-22CVE-2017-12193: The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users…
PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.45%
37.1th percentile
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.13.13-1 (bookworm) | linux 4.13.13-1 (bookworm) |
| linux | linux_kernel | < 4.13.11 | 4.13.11 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 3.13.0-153.203 | 3.13.0-153.203 |
| linux | linux_kernel | >= 0 < 4.4.0-104.127 | 4.4.0-104.127 |
| linux | linux_kernel | >= 0 < 4.4.0-103.126 | 4.4.0-103.126 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 7.1
CVE-2017-12154 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)
It was discovered that a race condition existed in the ALSA subsystem of
the Linux kernel when creating and deleting a port via ioctl(). A loc
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-07-02·CVSS 7.1
CVE-2017-12154 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3698-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local at
Ubuntu
Linux kernel regression
vendor_ubuntu·2017-12-15·CVSS 7.0
[HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: USN-3509-1 introduced a regression in the Linux kernel for Ubuntu 16.04 LTS.
USN-3509-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. Unfortunately, it also introduced a regression that prevented the
Ceph network filesystem from being used. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
Ubuntu
Linux kernel (Xenial HWE) regression
vendor_ubuntu·2017-12-15·CVSS 7.0
[HIGH] Linux kernel (Xenial HWE) regression
Title: Linux kernel (Xenial HWE) regression
Summary: USN-3509-2 introduced a regression in the Linux HWE kernel for Ubuntu 14.04 LTS.
USN-3509-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel for Ubuntu 14.04 LTS. Unfortunately, it also introduced a
regression that prevented the Ceph network filesystem from being
used. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A loc
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2017-12-08·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker co
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-12-07·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3509-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administra
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-12-07·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could us
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-12-07·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could us
Red Hat
kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation
vendor_redhat·2017-11-02·CVSS 5.5
CVE-2017-12193 [MEDIUM] CWE-476 kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation
kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.
A flaw was found in the Linux kernel's implementation of associative arrays introduced in 3.13. This functionality was backported to the 3.10 kernels in Red Hat Enterprise Linux 7. The flaw involved a null pointer dereference in assoc_array_apply_edit() due to incorrect node-splitting in assoc_array implementation. This affects the keyring key type and thus key
Debian
CVE-2017-12193: linux - The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the L...
vendor_debian·2017·CVSS 5.5
CVE-2017-12193 [MEDIUM] CVE-2017-12193: linux - The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the L...
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.
Scope: local
bookworm: resolved (fixed in 4.13.13-1)
bullseye: resolved (fixed in 4.13.13-1)
forky: resolved (fixed in 4.13.13-1)
sid: resolved (fixed in 4.13.13-1)
trixie: resolved (fixed in 4.13.13-1)
GHSA
GHSA-7c55-6mqj-q569: The assoc_array_insert_into_terminal_node function in lib/assoc_array
ghsa_unreviewed·2022-05-14
CVE-2017-12193 [MEDIUM] CWE-476 GHSA-7c55-6mqj-q569: The assoc_array_insert_into_terminal_node function in lib/assoc_array
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.
OSV
linux vulnerabilities
osv·2018-07-02·CVSS 7.1
CVE-2017-12154 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)
It was discovered that a race condition existed in the ALSA subsystem of
the Linux kernel when creating and deleting a port via ioctl(). A local
attacker could use this to cause a denial of service (system crash) or
possib
OSV
linux-lts-xenial, linux-aws regression
osv·2017-12-15·CVSS 7.0
[HIGH] linux-lts-xenial, linux-aws regression
linux-lts-xenial, linux-aws regression
USN-3509-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel for Ubuntu 14.04 LTS. Unfortunately, it also introduced a
regression that prevented the Ceph network filesystem from being
used. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain a
OSV
linux, linux-aws, linux-kvm, linux-raspi2 regression
osv·2017-12-15·CVSS 7.0
[HIGH] linux, linux-aws, linux-kvm, linux-raspi2 regression
linux, linux-aws, linux-kvm, linux-raspi2 regression
USN-3509-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. Unfortunately, it also introduced a regression that prevented the
Ceph network filesystem from being used. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain adminis
OSV
linux-gcp vulnerabilities
osv·2017-12-08·CVSS 7.0
CVE-2017-16939 [HIGH] linux-gcp vulnerabilities
linux-gcp vulnerabilities
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)
Eric B
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-12-07·CVSS 7.0
CVE-2017-16939 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial o
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2017-12-07·CVSS 7.0
[HIGH] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3509-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Z
OSV
CVE-2017-12193: The assoc_array_insert_into_terminal_node function in lib/assoc_array
osv·2017-11-22·CVSS 5.5
CVE-2017-12193 [MEDIUM] CVE-2017-12193: The assoc_array_insert_into_terminal_node function in lib/assoc_array
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.
Kernel
assoc_array: Fix a buggy node-splitting case
kernel_security·2017-10-11·CVSS 5.5
CVE-2017-12193 [MEDIUM] assoc_array: Fix a buggy node-splitting case
assoc_array: Fix a buggy node-splitting case
This fixes CVE-2017-12193.
Fix a case in the assoc_array implementation in which a new leaf is
added that needs to go into a node that happens to be full, where the
existing leaves in that node cluster together at that level to the
exclusion of new leaf.
What needs to happen is that the existing leaves get moved out to a new
node, N1, at level + 1 and the existing node needs replacing with one,
N0, that has pointers to the new leaf and to N1.
The code that tries to do this gets this wrong in two ways:
(1) The pointer that should've pointed from N0 to N1 is set to point
recursively to N0 instead.
(2) The backpointer from N0 needs to be set correctly in the case N0 is
either the root node or reached through a shortcut.
Fix this by removing
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12193 kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation [fedora-all]
bugzilla·2017-11-02·CVSS 5.5
CVE-2017-12193 [MEDIUM] CVE-2017-12193 kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation [fedora-all]
CVE-2017-12193 kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2017-12193 kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation
bugzilla·2017-10-12·CVSS 5.5
CVE-2017-12193 [MEDIUM] CVE-2017-12193 kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation
CVE-2017-12193 kernel: Null pointer dereference due to incorrect node-splitting in assoc_array implementation
A flaw was found in the Linux kernels implementation of associative arrays introduced in 3.13. The Red Hat Enterprise Linux 7 kernel had back ported this functionality to the 3.10 kernels and was affected by this flaw. The flaw involved a null pointer dereference in assoc_array_apply_edit() due to incorrect node-splitting in assoc_array implementation. This did not affect all callers of of the associative array code, only those that would try todereference the assigned value, a kernel panic will occur.
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ea6789980fdaa610d7eb63602c746bf6ec70cd2b
Oss-security:
http://seclists.org/oss-sec/20
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ea6789980fdaa610d7eb63602c746bf6ec70cd2bhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.11http://www.securityfocus.com/bid/101678https://access.redhat.com/errata/RHSA-2018:0151https://bugzilla.redhat.com/show_bug.cgi?id=1501215https://github.com/torvalds/linux/commit/ea6789980fdaa610d7eb63602c746bf6ec70cd2bhttps://usn.ubuntu.com/3698-1/https://usn.ubuntu.com/3698-2/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ea6789980fdaa610d7eb63602c746bf6ec70cd2bhttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.11http://www.securityfocus.com/bid/101678https://access.redhat.com/errata/RHSA-2018:0151https://bugzilla.redhat.com/show_bug.cgi?id=1501215https://github.com/torvalds/linux/commit/ea6789980fdaa610d7eb63602c746bf6ec70cd2bhttps://usn.ubuntu.com/3698-1/https://usn.ubuntu.com/3698-2/
2017-11-22
Published