CVE-2017-15115
published 2017-11-15CVE-2017-15115: The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.47%
38.0th percentile
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.13.13-1 (bookworm) | linux 4.13.13-1 (bookworm) |
| linux | linux_kernel | < 3.2.96 | 3.2.96 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 3.13.0-142.191 | 3.13.0-142.191 |
| linux | linux_kernel | >= 0 < 4.4.0-116.140 | 4.4.0-116.140 |
| linux | linux_kernel | >= 3.17 < 3.18.84 | 3.18.84 |
| linux | linux_kernel | >= 3.19 < 4.1.47 | 4.1.47 |
| linux | linux_kernel | >= 3.3 < 3.16.51 | 3.16.51 |
| linux | linux_kernel | >= 4.10 < 4.13.16 | 4.13.16 |
| linux | linux_kernel | >= 4.2 < 4.4.100 | 4.4.100 |
| linux | linux_kernel | >= 4.5 < 4.9.65 | 4.9.65 |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2018-02-23·CVSS 7.8
CVE-2017-15115 [HIGH] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
ChunYu Wang discovered that a use-after-free vulnerability existed in the
SCTP protocol implementation in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code, (CVE-2017-15115)
Mohamed Ghannam discovered a use-after-free vulnerability in the DCCP
protocol implementation in the Linux kernel. A local attacker could use
this to cause a
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-23·CVSS 7.8
CVE-2017-0750 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that an out-of-bounds write vulnerability existed in the
Flash-Friendly File System (f2fs) in the Linux kernel. An attacker could
construct a malicious file system that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2017-0750)
It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-0861)
It was discovered that the KVM implementation in the Linux kernel allowed
passthrough of the diagnostic I/O port 0x80. An attacke
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-02-23·CVSS 7.8
CVE-2017-0750 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3583-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that an out-of-bounds write vulnerability existed in the
Flash-Friendly File System (f2fs) in the Linux kernel. An attacker could
construct a malicious file system that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2017-0750)
It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 7.8
CVE-2017-15115 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
ChunYu Wang discovered that a use-after-free vulnerability existed
in the SCTP protocol implementation in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code, (CVE-2017-15115)
Mohamed Ghannam discovered a use-after-free vulnerability in the DCCP
protocol implementation in the Linux kernel. A local attacker could use
this to cause a denial of servic
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 7.8
CVE-2017-15115 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3581-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
ChunYu Wang discovered that a use-after-free vulnerability existed
in the SCTP protocol implementation in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash)
or possibly exec
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of serv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.5
CVE-2015-8952 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory e
Red Hat
kernel: use-after-free in sctp_cmp_addr_exact
vendor_redhat·2017-10-17·CVSS 7.8
CVE-2017-15115 [HIGH] CWE-416 kernel: use-after-free in sctp_cmp_addr_exact
kernel: use-after-free in sctp_cmp_addr_exact
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
A vulnerability was found in the Linux kernel when peeling off an association to the socket in another network namespace. All transports in this association are not to be rehashed and keep using the old key in hashtable, thus removing transports from hashtable when closing the socket, all transports are being freed. Later on a use-after-free issue could be caused when looking up an association and dereferencing the transports.
Statement:
Debian
CVE-2017-15115: linux - The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.1...
vendor_debian·2017·CVSS 7.8
CVE-2017-15115 [HIGH] CVE-2017-15115: linux - The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.1...
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
Scope: local
bookworm: resolved (fixed in 4.13.13-1)
bullseye: resolved (fixed in 4.13.13-1)
forky: resolved (fixed in 4.13.13-1)
sid: resolved (fixed in 4.13.13-1)
trixie: resolved (fixed in 4.13.13-1)
GHSA
GHSA-chgx-7ppx-v6gh: The sctp_do_peeloff function in net/sctp/socket
ghsa_unreviewed·2022-05-14
CVE-2017-15115 [HIGH] CWE-416 GHSA-chgx-7ppx-v6gh: The sctp_do_peeloff function in net/sctp/socket
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
OSV
linux vulnerabilities
osv·2018-02-23·CVSS 7.8
CVE-2017-0750 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that an out-of-bounds write vulnerability existed in the
Flash-Friendly File System (f2fs) in the Linux kernel. An attacker could
construct a malicious file system that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2017-0750)
It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-0861)
It was discovered that the KVM implementation in the Linux kernel allowed
passthrough of the diagnostic I/O port 0x80. An attacker in a guest VM
could use this to cause a denial of service (system crash) in th
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-02-22·CVSS 5.5
CVE-2017-17712 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2017-1219
OSV
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
osv·2018-02-22·CVSS 7.8
[HIGH] linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
USN-3581-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
ChunYu Wang discovered that a use-after-free vulnerability existed
in the SCTP protocol implementation in the Linux kernel. A local
attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code, (CVE-2017-15115)
Mohamed G
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-02-22·CVSS 5.5
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsys
OSV
CVE-2017-15115: The sctp_do_peeloff function in net/sctp/socket
osv·2017-11-15·CVSS 7.8
CVE-2017-15115 [HIGH] CVE-2017-15115: The sctp_do_peeloff function in net/sctp/socket
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15115 kernel: use-after-free in sctp_cmp_addr_exact [fedora-all]
bugzilla·2017-11-15·CVSS 7.8
CVE-2017-15115 [HIGH] CVE-2017-15115 kernel: use-after-free in sctp_cmp_addr_exact [fedora-all]
CVE-2017-15115 kernel: use-after-free in sctp_cmp_addr_exact [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2017-15115 kernel: use-after-free in sctp_cmp_addr_exact
bugzilla·2017-11-15·CVSS 7.8
CVE-2017-15115 [HIGH] CVE-2017-15115 kernel: use-after-free in sctp_cmp_addr_exact
CVE-2017-15115 kernel: use-after-free in sctp_cmp_addr_exact
It was found that in Linux kernel when peeling off an association to the socket in another network namespace, all transports in this association are not to be rehashed and keep use the old key in hashtable. A kernel would miss removing transports from hashtable when closing the socket and all transports are being freed. Later on a use-after-free issue could be caused when looking up an association and dereferencing the transports.
References:
https://patchwork.ozlabs.org/patch/827077/
http://seclists.org/oss-sec/2017/q4/282
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=df80cd9b28b9ebaa284a41df611dbf3a2d05ca74
Discussion:
Acknowledgments:
Name: ChunYu Wang (Red Hat)
---
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=df80cd9b28b9ebaa284a41df611dbf3a2d05ca74http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://seclists.org/oss-sec/2017/q4/282http://www.securityfocus.com/bid/101877https://bugzilla.redhat.com/show_bug.cgi?id=1513345https://github.com/torvalds/linux/commit/df80cd9b28b9ebaa284a41df611dbf3a2d05ca74https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlhttps://patchwork.ozlabs.org/patch/827077/https://source.android.com/security/bulletin/pixel/2018-04-01https://usn.ubuntu.com/3581-1/https://usn.ubuntu.com/3581-2/https://usn.ubuntu.com/3581-3/https://usn.ubuntu.com/3582-1/https://usn.ubuntu.com/3582-2/https://usn.ubuntu.com/3583-1/https://usn.ubuntu.com/3583-2/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=df80cd9b28b9ebaa284a41df611dbf3a2d05ca74http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://seclists.org/oss-sec/2017/q4/282http://www.securityfocus.com/bid/101877https://bugzilla.redhat.com/show_bug.cgi?id=1513345https://github.com/torvalds/linux/commit/df80cd9b28b9ebaa284a41df611dbf3a2d05ca74https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlhttps://patchwork.ozlabs.org/patch/827077/https://source.android.com/security/bulletin/pixel/2018-04-01https://usn.ubuntu.com/3581-1/https://usn.ubuntu.com/3581-2/https://usn.ubuntu.com/3581-3/https://usn.ubuntu.com/3582-1/https://usn.ubuntu.com/3582-2/https://usn.ubuntu.com/3583-1/https://usn.ubuntu.com/3583-2/
2017-11-15
Published