CVE-2017-15306
published 2017-11-06CVE-2017-15306: The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service…
PriorityP417medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.39%
32.3th percentile
The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a KVM_CHECK_EXTENSION KVM_CAP_PPC_HTM ioctl call to /dev/kvm.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.13.13-1 (bookworm) | linux 4.13.13-1 (bookworm) |
| linux | linux_kernel | <= 4.13.10 | — |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2017-12-08·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker co
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-12-07·CVSS 7.0
CVE-2017-1000405 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could us
Red Hat
Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform
vendor_redhat·2017-11-06·CVSS 5.5
CVE-2017-15306 [MEDIUM] CWE-476 Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform
Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform
The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a KVM_CHECK_EXTENSION KVM_CAP_PPC_HTM ioctl call to /dev/kvm.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2017-15306: linux - The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the L...
vendor_debian·2017·CVSS 5.5
CVE-2017-15306 [MEDIUM] CVE-2017-15306: linux - The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the L...
The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a KVM_CHECK_EXTENSION KVM_CAP_PPC_HTM ioctl call to /dev/kvm.
Scope: local
bookworm: resolved (fixed in 4.13.13-1)
bullseye: resolved (fixed in 4.13.13-1)
forky: resolved (fixed in 4.13.13-1)
sid: resolved (fixed in 4.13.13-1)
trixie: resolved (fixed in 4.13.13-1)
GHSA
GHSA-5jfh-37mq-mfw7: The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc
ghsa_unreviewed·2022-05-17
CVE-2017-15306 [MEDIUM] CWE-476 GHSA-5jfh-37mq-mfw7: The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc
The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a KVM_CHECK_EXTENSION KVM_CAP_PPC_HTM ioctl call to /dev/kvm.
OSV
linux-gcp vulnerabilities
osv·2017-12-08·CVSS 7.0
CVE-2017-16939 [HIGH] linux-gcp vulnerabilities
linux-gcp vulnerabilities
Mohamed Ghannam discovered that a use-after-free vulnerability existed in
the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-16939)
It was discovered that the Linux kernel did not properly handle copy-on-
write of transparent huge pages. A local attacker could use this to cause a
denial of service (application crashes) or possibly gain administrative
privileges. (CVE-2017-1000405)
Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)
Eric B
OSV
CVE-2017-15306: The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc
osv·2017-11-06·CVSS 5.5
CVE-2017-15306 [MEDIUM] CVE-2017-15306: The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc
The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a KVM_CHECK_EXTENSION KVM_CAP_PPC_HTM ioctl call to /dev/kvm.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15306 Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform [fedora-all]
bugzilla·2017-11-07·CVSS 5.5
CVE-2017-15306 [MEDIUM] CVE-2017-15306 Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform [fedora-all]
CVE-2017-15306 Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2017-15306 Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform
bugzilla·2017-11-07·CVSS 5.5
CVE-2017-15306 [MEDIUM] CVE-2017-15306 Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform
CVE-2017-15306 Kernel: KVM: oops when checking KVM_CAP_PPC_HTM on PPC platform
Linux kernel built with the KVM virtualization(CONFIG_KVM) support
for PowerPC platform(CONFIG_PPC), is vulnerable to a NULL pointer
de-reference issue. It could occur when an unprivileged user attempts
to check if the PPC hardware supports Transactional Memory(KVM_CAP_PPC_HTM).
An unprivileged user could use this flaw to crash the kernel resulting
in DoS scenario.
Upstream patch:
-> https://git.kernel.org/linus/ac64115a66c18c01745bbd3c47a36b124e5fd8c0
Reference:
-> http://www.openwall.com/lists/oss-security/2017/11/06/6
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1510400]
---
Statement:
This issue does not affect the versions of the kernel package as shipped with
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ac64115a66c18c01745bbd3c47a36b124e5fd8c0http://openwall.com/lists/oss-security/2017/11/06/6http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.11http://www.securityfocus.com/bid/101693https://github.com/torvalds/linux/commit/ac64115a66c18c01745bbd3c47a36b124e5fd8c0http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ac64115a66c18c01745bbd3c47a36b124e5fd8c0http://openwall.com/lists/oss-security/2017/11/06/6http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.11http://www.securityfocus.com/bid/101693https://github.com/torvalds/linux/commit/ac64115a66c18c01745bbd3c47a36b124e5fd8c0
2017-11-06
Published