CVE-2017-13305
published 2018-04-04CVE-2017-13305: A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
PriorityP426high7.1CVSS 3.0
AVLACLPRLUINSUCHINAH
EPSS
0.32%
23.9th percentile
A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.12.6-1 (bookworm) | linux 4.12.6-1 (bookworm) |
| google_inc | android | — | — |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 3.13.0-149.199 | 3.13.0-149.199 |
| linux | linux_kernel | >= 0 < 4.4.0-121.145 | 4.4.0-121.145 |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-05-22·CVSS 8.8
CVE-2017-12134 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
USN-3655-1 fixed vulnerabilities and added mitigations in the Linux
kernel for Ubuntu 14.04 LTS. This update provides the corresponding
updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu
14.04 LTS for Ubuntu 12.04 ESM.
Jann Horn and Ken Johnson discovered that microprocessors utilizing
speculative execution of a memory read may allow unauthorized memory
reads via a sidechannel attack. This flaw is known as Spectre
Variant 4. A local attacker could use this to expose sensitive
information, including kernel memory. (CVE-2018-3639)
Jan H. Schönherr discovered that the Xen subsystem did not properly handle
block IO merges correctly in some situations. An att
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-05-22·CVSS 8.8
CVE-2017-12134 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
Jann Horn and Ken Johnson discovered that microprocessors utilizing
speculative execution of a memory read may allow unauthorized memory
reads via a sidechannel attack. This flaw is known as Spectre
Variant 4. A local attacker could use this to expose sensitive
information, including kernel memory. (CVE-2018-3639)
Jan H. Schönherr discovered that the Xen subsystem did not properly handle
block IO merges correctly in some situations. An attacker in a guest vm
could use this to cause a denial of service (host crash) or possibly gain
administrative privileges in the host. (CVE-2017-12134)
It was discovered that the Bluetooth HIP Protocol implementation in the
Linux kernel did not prope
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code.
Red Hat
kernel: Buffer over-read in keyring subsystem allows exposing potentially sensitive information to local attacker
vendor_redhat·2017-06-08·CVSS 7.1
CVE-2017-13305 [HIGH] CWE-125 kernel: Buffer over-read in keyring subsystem allows exposing potentially sensitive information to local attacker
kernel: Buffer over-read in keyring subsystem allows exposing potentially sensitive information to local attacker
A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
A flaw has been identified in the Linux kernel's implementation of valid_master_desc() in which a memory buffer would be compared to a userspace value with an incorrect size of comparison. By bruteforcing the comparison, an attacker could determine what was in memory after the description and possibly obtain sensitive information from kernel memory.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-13305: linux - A information disclosure vulnerability in the Upstream kernel encrypted-keys. Pr...
vendor_debian·2017·CVSS 7.1
CVE-2017-13305 [HIGH] CVE-2017-13305: linux - A information disclosure vulnerability in the Upstream kernel encrypted-keys. Pr...
A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.6-1)
forky: resolved (fixed in 4.12.6-1)
sid: resolved (fixed in 4.12.6-1)
trixie: resolved (fixed in 4.12.6-1)
GHSA
GHSA-2fvp-7f4c-65qh: A information disclosure vulnerability in the Upstream kernel encrypted-keys
ghsa_unreviewed·2022-05-13
CVE-2017-13305 [HIGH] CWE-125 GHSA-2fvp-7f4c-65qh: A information disclosure vulnerability in the Upstream kernel encrypted-keys
A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
OSV
linux vulnerabilities
osv·2018-05-22·CVSS 8.8
CVE-2018-3639 [HIGH] linux vulnerabilities
linux vulnerabilities
Jann Horn and Ken Johnson discovered that microprocessors utilizing
speculative execution of a memory read may allow unauthorized memory
reads via a sidechannel attack. This flaw is known as Spectre
Variant 4. A local attacker could use this to expose sensitive
information, including kernel memory. (CVE-2018-3639)
Jan H. Schönherr discovered that the Xen subsystem did not properly handle
block IO merges correctly in some situations. An attacker in a guest vm
could use this to cause a denial of service (host crash) or possibly gain
administrative privileges in the host. (CVE-2017-12134)
It was discovered that the Bluetooth HIP Protocol implementation in the
Linux kernel did not properly validate HID connection setup information. An
attacker could use this to cause a
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a denial of
service (system
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-04-24·CVSS 7.1
CVE-2017-13305 [HIGH] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)
It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)
Luo Quan and Wei Yang discovered that a race conditi
OSV
CVE-2017-13305: A information disclosure vulnerability in the Upstream kernel encrypted-keys
osv·2018-04-04·CVSS 7.1
CVE-2017-13305 [HIGH] CVE-2017-13305: A information disclosure vulnerability in the Upstream kernel encrypted-keys
A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2018:2165https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttps://source.android.com/security/bulletin/pixel/2018-04-01https://usn.ubuntu.com/3631-1/https://usn.ubuntu.com/3631-2/https://usn.ubuntu.com/3655-1/https://usn.ubuntu.com/3655-2/https://access.redhat.com/errata/RHSA-2018:2165https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttps://source.android.com/security/bulletin/pixel/2018-04-01https://usn.ubuntu.com/3631-1/https://usn.ubuntu.com/3631-2/https://usn.ubuntu.com/3655-1/https://usn.ubuntu.com/3655-2/
2018-04-04
Published