CVE-2017-13215
published 2018-01-12CVE-2017-13215: A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
22.8th percentile
A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.4.2-1 (bookworm) | linux 4.4.2-1 (bookworm) |
| android | — | — | |
| google_inc | android | — | — |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
| linux | linux_kernel | >= 0 < 4.4.2-1 | 4.4.2-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: crypto: privilege escalation in skcipher_recvmsg function
vendor_redhat·2018-01-02·CVSS 7.8
CVE-2017-13215 [HIGH] CWE-287 kernel: crypto: privilege escalation in skcipher_recvmsg function
kernel: crypto: privilege escalation in skcipher_recvmsg function
A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
A flaw was found in the Linux kernel's skcipher component, which affects the skcipher_recvmsg function. Attackers using a specific input can lead to a privilege escalation.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6, and kernel-alt packages.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7, MRG-2 and real-time kernels.
Future Linux kernel updates for the respective releases may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not
Android
CVE-2017-13215: Skcipher
vendor_android·2018-01-01·CVSS 7.8
CVE-2017-13215 [HIGH] CVE-2017-13215: Skcipher
Android Security Bulletin 2018-01-01
CVE: CVE-2017-13215
Severity: HIGH
Type: EoP
Component: Skcipher
References: A-64386293
Upstream kernel
Debian
CVE-2017-13215: linux - A elevation of privilege vulnerability in the Upstream kernel skcipher. Product:...
vendor_debian·2017·CVSS 7.8
CVE-2017-13215 [HIGH] CVE-2017-13215: linux - A elevation of privilege vulnerability in the Upstream kernel skcipher. Product:...
A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
GHSA
GHSA-xpjw-vcgc-qx6p: A elevation of privilege vulnerability in the Upstream kernel skcipher
ghsa_unreviewed·2022-05-13
CVE-2017-13215 [HIGH] GHSA-xpjw-vcgc-qx6p: A elevation of privilege vulnerability in the Upstream kernel skcipher
A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
OSV
CVE-2017-13215: A elevation of privilege vulnerability in the Upstream kernel skcipher
osv·2018-01-12·CVSS 7.8
CVE-2017-13215 [HIGH] CVE-2017-13215: A elevation of privilege vulnerability in the Upstream kernel skcipher
A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-13215 kernel: crypto: privilege escalation in skcipher_recvmsg function
bugzilla·2018-01-16·CVSS 7.8
CVE-2017-13215 [HIGH] CVE-2017-13215 kernel: crypto: privilege escalation in skcipher_recvmsg function
CVE-2017-13215 kernel: crypto: privilege escalation in skcipher_recvmsg function
A flaw was found in the upstream kernel Skcipher component. This vulnerability affects the skcipher_recvmsg function of the component Skcipher. The manipulation with an unknown input leads to a privilege escalation vulnerability
References:
https://source.android.com/security/bulletin/2018-01-01
Patch:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?h=v3.18.78&id=36c84b22ac8aa041cbdfbe48a55ebb32e3521704
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f0414e54e4d1893c6f08260693f8ef84c929293
Discussion:
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6, and kernel-alt packages.
Thi
arXiv
Partially-Observable Security Games for Automating Attack-Defense Analysis
arxiv_fulltext·2022-11-02
Partially-Observable Security Games for Automating Attack-Defense Analysis
Partially-Observable Security Games for Automating Attack-Defense Analysis
Narges Khakpour
[email protected]
School of Computing, Newcastle University
Newcastle upon Tyne
UK
Department of Computer Science and Media Technology, Linnaeus University
Växjö
Sweden
David Parker
[email protected]
Department of Computer Science, Oxford University
Oxford
UK
## Abstract
Network systems often contain vulnerabilities that remain unfixed in a network for various reasons, such as the lack of a patch or knowledge to fix them. With the presence of such residual vulnerabilities, the network administrator should properly react to the malicious activities or proactively prevent them, by applying suitable countermeasures that minimize the likelihood of an attack by the attacker. In this
http://www.securityfocus.com/bid/102390http://www.securitytracker.com/id/1040106https://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2019:1170https://access.redhat.com/errata/RHSA-2019:1190https://source.android.com/security/bulletin/2018-01-01http://www.securityfocus.com/bid/102390http://www.securitytracker.com/id/1040106https://access.redhat.com/errata/RHSA-2018:2384https://access.redhat.com/errata/RHSA-2018:2395https://access.redhat.com/errata/RHSA-2019:1170https://access.redhat.com/errata/RHSA-2019:1190https://source.android.com/security/bulletin/2018-01-01
2018-01-12
Published