CVE-2017-14497
published 2017-09-15CVE-2017-14497: The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of…
PriorityP433high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.56%
43.2th percentile
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.12.13-1 (bookworm) | linux 4.12.13-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.12.13-1 | 4.12.13-1 |
| linux | linux_kernel | >= 0 < 4.12.13-1 | 4.12.13-1 |
| linux | linux_kernel | >= 0 < 4.12.13-1 | 4.12.13-1 |
| linux | linux_kernel | >= 0 < 4.12.13-1 | 4.12.13-1 |
| linux | linux_kernel | >= 4.10 < 4.12.14 | 4.12.14 |
| linux | linux_kernel | >= 4.6 < 4.9.51 | 4.9.51 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-14497: TCP packet processing
vendor_android·2018-01-01·CVSS 7.8
CVE-2017-14497 [HIGH] CVE-2017-14497: TCP packet processing
Android Security Bulletin 2018-01-01
CVE: CVE-2017-14497
Severity: HIGH
Type: EoP
Component: TCP packet processing
References: A-66694921
Upstream kernel
Red Hat
kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c
vendor_redhat·2017-08-28·CVSS 7.8
CVE-2017-14497 [HIGH] CWE-122 kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c
kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
A buffer overflow was discovered in tpacket_rcv() function in the Linux kernel since v4.6-rc1 through v4.13. A number of socket-related syscalls can be made to set up a configuration when each packet received by a network interface can cause writing up to 10 bytes to a kernel memory outside of a kernel buffer. This can cause unspecified kernel data corruption effects, including damage of in-memory and on-disk XFS data.
Statement: This issue
Debian
CVE-2017-14497: linux - The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4....
vendor_debian·2017·CVSS 7.8
CVE-2017-14497 [HIGH] CVE-2017-14497: linux - The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4....
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
Scope: local
bookworm: resolved (fixed in 4.12.13-1)
bullseye: resolved (fixed in 4.12.13-1)
forky: resolved (fixed in 4.12.13-1)
sid: resolved (fixed in 4.12.13-1)
trixie: resolved (fixed in 4.12.13-1)
GHSA
GHSA-883m-49fj-jg3j: The tpacket_rcv function in net/packet/af_packet
ghsa_unreviewed·2022-05-14
CVE-2017-14497 [HIGH] CWE-119 GHSA-883m-49fj-jg3j: The tpacket_rcv function in net/packet/af_packet
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
OSV
CVE-2017-14497: The tpacket_rcv function in net/packet/af_packet
osv·2017-09-15·CVSS 7.8
CVE-2017-14497 [HIGH] CVE-2017-14497: The tpacket_rcv function in net/packet/af_packet
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14497 kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c [fedora-all]
bugzilla·2017-09-18·CVSS 7.8
CVE-2017-14497 [HIGH] CVE-2017-14497 kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c [fedora-all]
CVE-2017-14497 kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2017-14497 kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c
bugzilla·2017-09-18·CVSS 7.8
CVE-2017-14497 [HIGH] CVE-2017-14497 kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c
CVE-2017-14497 kernel: buffer overflow in tpacket_rcv() in net/packet/af_packet.c
A buffer overflow was discovered in tpacket_rcv() function in the Linux kernel since v4.6-rc1 through v4.13. A number of socket-related syscalls can be made to set up a configuration when each packet received by a network interface can cause writing up to 10 bytes to a kernel memory outside of a kernel buffer. This can cause unspecified kernel data corruption effects, including damage of in-memory and on-disk XFS data.
References:
https://marc.info/?l=linux-kernel&m=150394500728906&w=2
https://marc.info/?t=150394517700001&r=1&w=2
http://seclists.org/oss-sec/2017/q3/476
A kernel patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=edbd58be15a957f6a760c4a514cd475217eb97fd
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=edbd58be15a957f6a760c4a514cd475217eb97fdhttp://seclists.org/oss-sec/2017/q3/476http://www.debian.org/security/2017/dsa-3981http://www.securityfocus.com/bid/100871http://www.securitytracker.com/id/1039371http://www.securitytracker.com/id/1040106https://bugzilla.redhat.com/show_bug.cgi?id=1492593https://github.com/torvalds/linux/commit/edbd58be15a957f6a760c4a514cd475217eb97fdhttps://marc.info/?l=linux-kernel&m=150394500728906&w=2https://marc.info/?t=150394517700001&r=1&w=2https://source.android.com/security/bulletin/2018-01-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=edbd58be15a957f6a760c4a514cd475217eb97fdhttp://seclists.org/oss-sec/2017/q3/476http://www.debian.org/security/2017/dsa-3981http://www.securityfocus.com/bid/100871http://www.securitytracker.com/id/1039371http://www.securitytracker.com/id/1040106https://bugzilla.redhat.com/show_bug.cgi?id=1492593https://github.com/torvalds/linux/commit/edbd58be15a957f6a760c4a514cd475217eb97fdhttps://marc.info/?l=linux-kernel&m=150394500728906&w=2https://marc.info/?t=150394517700001&r=1&w=2https://source.android.com/security/bulletin/2018-01-01
2017-09-15
Published