CVE-2017-13715
published 2017-08-29CVE-2017-13715: The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.65%
95.0th percentile
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a single crafted MPLS packet.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.1-1 (bookworm) | linux 4.3.1-1 (bookworm) |
| chrome_chrome | — | — | |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
| linux | linux_kernel | >= 4.2 < 4.3 | 4.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x582-23f7-w3cc: The __skb_flow_dissect function in net/core/flow_dissector
ghsa_unreviewed·2022-05-13
CVE-2017-13715 [CRITICAL] CWE-665 GHSA-x582-23f7-w3cc: The __skb_flow_dissect function in net/core/flow_dissector
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a single crafted MPLS packet.
OSV
CVE-2017-13715: The __skb_flow_dissect function in net/core/flow_dissector
osv·2017-08-29·CVSS 9.8
CVE-2017-13715 [CRITICAL] CVE-2017-13715: The __skb_flow_dissect function in net/core/flow_dissector
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a single crafted MPLS packet.
Chrome
Stable Channel Update for Desktop: CVE-2019-13715
vendor_chrome·2019-10-22·CVSS 4.3
CVE-2019-13715 [LOW] Stable Channel Update for Desktop: CVE-2019-13715
Stable Channel Update for Desktop
CVE-2019-13715: Address bar spoofing. Reported by xisigr of Tencent's Xuanwu Lab on 2017-08-31
[$500][ 1005948 ] Low CVE-2019-13716: Service worker state error
Reported by Barron Hagerman on 2019-09-19
Severity: low
Debian
CVE-2017-13715: linux - The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel...
vendor_debian·2017·CVSS 9.8
CVE-2017-13715 [CRITICAL] CVE-2017-13715: linux - The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel...
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a single crafted MPLS packet.
Scope: local
bookworm: resolved (fixed in 4.3.1-1)
bullseye: resolved (fixed in 4.3.1-1)
forky: resolved (fixed in 4.3.1-1)
sid: resolved (fixed in 4.3.1-1)
trixie: resolved (fixed in 4.3.1-1)
Red Hat
kernel: Use of uninitialized value in __skb_flow_dissect()
vendor_redhat·2015-09-01·CVSS 9.8
CVE-2017-13715 [CRITICAL] CWE-456 kernel: Use of uninitialized value in __skb_flow_dissect()
kernel: Use of uninitialized value in __skb_flow_dissect()
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a single crafted MPLS packet.
It was found that in the Linux kernel version 4.2-rc1 to 4.3-rc1, a use of uninitialized 'n_proto', 'ip_proto', and 'thoff' variables in __skb_flow_dissect() function can lead to a remote denial-of-service via malformed MPLS packet.
Statement: This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 as the code with the flaw is not present or is already
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a6e544b0a88b53114bfa5a57e21b7be7a8dfc9d0http://seclists.org/oss-sec/2017/q3/345http://www.securityfocus.com/bid/100517https://github.com/torvalds/linux/commit/a6e544b0a88b53114bfa5a57e21b7be7a8dfc9d0http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a6e544b0a88b53114bfa5a57e21b7be7a8dfc9d0http://seclists.org/oss-sec/2017/q3/345http://www.securityfocus.com/bid/100517https://github.com/torvalds/linux/commit/a6e544b0a88b53114bfa5a57e21b7be7a8dfc9d0
2017-08-29
Published