CVE-2017-14106
published 2017-09-01CVE-2017-14106: The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window…
PriorityP417medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.45%
36.7th percentile
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.12.6-1 (bookworm) | linux 4.12.6-1 (bookworm) |
| linux | linux_kernel | <= 4.11.12 | — |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 4.12.6-1 | 4.12.6-1 |
| linux | linux_kernel | >= 0 < 3.13.0-133.182 | 3.13.0-133.182 |
| linux | linux_kernel | >= 0 < 4.4.0-97.120 | 4.4.0-97.120 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (GCP) vulnerability
vendor_ubuntu·2017-10-11·CVSS 5.5
CVE-2017-14106 [MEDIUM] Linux kernel (GCP) vulnerability
Title: Linux kernel (GCP) vulnerability
Summary: The system could be made to crash under certain conditions.
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard syst
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 6.8
CVE-2016-8633 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3445-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation
in the Linux kernel contained a buffer overflow when handling fragmented
packets. A remote attacker could use this to possibly execute arbitrary
code with administrative privileges. (CVE-2016-8633)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (C
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-10·CVSS 8.8
CVE-2017-12134 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jan H. Schönherr discovered that the Xen subsystem did not properly handle
block IO merges correctly in some situations. An attacker in a guest vm
could use this to cause a denial of service (host crash) or possibly gain
administrative privileges in the host. (CVE-2017-12134)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
Otto Ebeling discovered that the memory manager in the Linux kernel did not
properly check the effective UID in some situations. A local attacker could
use this to expose sensitive information. (CVE-2017-141
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-10·CVSS 6.8
CVE-2016-8633 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation
in the Linux kernel contained a buffer overflow when handling fragmented
packets. A remote attacker could use this to possibly execute arbitrary
code with administrative privileges. (CVE-2016-8633)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version numb
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-10·CVSS 5.5
CVE-2017-1000255 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that on the PowerPC architecture, the kernel did not
properly sanitize the signal stack when handling sigreturn(). A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-1000255)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-10-10·CVSS 5.5
CVE-2017-1000255 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3443-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS.
It was discovered that on the PowerPC architecture, the kernel did not
properly sanitize the signal stack when handling sigreturn(). A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-1000255)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
Instruct
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-10-10·CVSS 8.8
CVE-2017-12134 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3444-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Jan H. Schönherr discovered that the Xen subsystem did not properly handle
block IO merges correctly in some situations. An attacker in a guest vm
could use this to cause a denial of service (host crash) or possibly gain
administrative privileges in the host. (CVE-2017-12134)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash)
Red Hat
kernel: Divide-by-zero in __tcp_select_window
vendor_redhat·2017-09-01·CVSS 5.5
CVE-2017-14106 [MEDIUM] CWE-369 kernel: Divide-by-zero in __tcp_select_window
kernel: Divide-by-zero in __tcp_select_window
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
A divide-by-zero vulnerability was found in the __tcp_select_window function in the Linux kernel. This can result in a kernel panic causing a local denial of service.
Statement: This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and 7 and MRG-2. Future Linux kernel updates for the respective releases may address this issue.
Package: kernel-alt (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2017-14106: linux - The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 al...
vendor_debian·2017·CVSS 5.5
CVE-2017-14106 [MEDIUM] CVE-2017-14106: linux - The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 al...
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.6-1)
forky: resolved (fixed in 4.12.6-1)
sid: resolved (fixed in 4.12.6-1)
trixie: resolved (fixed in 4.12.6-1)
GHSA
GHSA-fwvw-9m43-mj3m: The tcp_disconnect function in net/ipv4/tcp
ghsa_unreviewed·2022-05-14
CVE-2017-14106 [MEDIUM] CWE-369 GHSA-fwvw-9m43-mj3m: The tcp_disconnect function in net/ipv4/tcp
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
OSV
linux-gcp vulnerability
osv·2017-10-11·CVSS 5.5
CVE-2017-14106 [MEDIUM] linux-gcp vulnerability
linux-gcp vulnerability
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
OSV
linux-lts-xenial vulnerabilities
osv·2017-10-10·CVSS 8.8
[HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3444-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Jan H. Schönherr discovered that the Xen subsystem did not properly handle
block IO merges correctly in some situations. An attacker in a guest vm
could use this to cause a denial of service (host crash) or possibly gain
administrative privileges in the host. (CVE-2017-12134)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
Otto Ebeling discovered that the memory manager in the Linux k
OSV
linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-10-10·CVSS 8.8
CVE-2017-12134 [HIGH] linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Jan H. Schönherr discovered that the Xen subsystem did not properly handle
block IO merges correctly in some situations. An attacker in a guest vm
could use this to cause a denial of service (host crash) or possibly gain
administrative privileges in the host. (CVE-2017-12134)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
Otto Ebeling discovered that the memory manager in the Linux kernel did not
properly check the effective UID in some situations. A local attacker could
use this to expose sensitive information. (CVE-2017-14140)
OSV
linux vulnerabilities
osv·2017-10-10·CVSS 6.8
CVE-2016-8633 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation
in the Linux kernel contained a buffer overflow when handling fragmented
packets. A remote attacker could use this to possibly execute arbitrary
code with administrative privileges. (CVE-2016-8633)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
OSV
linux-hwe vulnerabilities
osv·2017-10-10·CVSS 5.5
CVE-2017-1000255 [MEDIUM] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3443-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS.
It was discovered that on the PowerPC architecture, the kernel did not
properly sanitize the signal stack when handling sigreturn(). A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-1000255)
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP
stack implementation in the Linux kernel. A local attacker could use this
to cause a denial of service (system crash). (CVE-2017-14106)
OSV
CVE-2017-14106: The tcp_disconnect function in net/ipv4/tcp
osv·2017-09-01·CVSS 5.5
CVE-2017-14106 [MEDIUM] CVE-2017-14106: The tcp_disconnect function in net/ipv4/tcp
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14106 kernel: Divide-by-zero in __tcp_select_window [fedora-all]
bugzilla·2017-09-01·CVSS 5.5
CVE-2017-14106 [MEDIUM] CVE-2017-14106 kernel: Divide-by-zero in __tcp_select_window [fedora-all]
CVE-2017-14106 kernel: Divide-by-zero in __tcp_select_window [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2017-14106 kernel: Divide-by-zero in __tcp_select_window
bugzilla·2017-08-31·CVSS 5.5
CVE-2017-14106 [MEDIUM] CVE-2017-14106 kernel: Divide-by-zero in __tcp_select_window
CVE-2017-14106 kernel: Divide-by-zero in __tcp_select_window
Divide-by-zero vulnerability was found in __tcp_select_window function which can result into kernel panic causing local denial-of-service if panic_on_oops is enabled.
References:
http://seclists.org/oss-sec/2017/q3/389
https://marc.info/?l=linux-netdev&m=150415901823078
https://www.mail-archive.com/[email protected]/msg186255.html
https://groups.google.com/forum/#!topic/syzkaller/e4SrsEBEziQ
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=499350a5a6e7512d9ed369ed63a4244b6536f4f8
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1487703]
---
Statement:
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linu
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=499350a5a6e7512d9ed369ed63a4244b6536f4f8http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://www.debian.org/security/2017/dsa-3981http://www.securityfocus.com/bid/100878http://www.securitytracker.com/id/1039549https://access.redhat.com/errata/RHSA-2017:2918https://access.redhat.com/errata/RHSA-2017:2930https://access.redhat.com/errata/RHSA-2017:2931https://access.redhat.com/errata/RHSA-2017:3200https://access.redhat.com/errata/RHSA-2018:2172https://github.com/torvalds/linux/commit/499350a5a6e7512d9ed369ed63a4244b6536f4f8https://www.mail-archive.com/netdev%40vger.kernel.org/msg186255.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=499350a5a6e7512d9ed369ed63a4244b6536f4f8http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://www.debian.org/security/2017/dsa-3981http://www.securityfocus.com/bid/100878http://www.securitytracker.com/id/1039549https://access.redhat.com/errata/RHSA-2017:2918https://access.redhat.com/errata/RHSA-2017:2930https://access.redhat.com/errata/RHSA-2017:2931https://access.redhat.com/errata/RHSA-2017:3200https://access.redhat.com/errata/RHSA-2018:2172https://github.com/torvalds/linux/commit/499350a5a6e7512d9ed369ed63a4244b6536f4f8https://www.mail-archive.com/netdev%40vger.kernel.org/msg186255.html
2017-09-01
Published