CVE-2017-2618
published 2018-07-27CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.46%
37.4th percentile
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 4.9.10-1 (bookworm) | linux 4.9.10-1 (bookworm) |
| linux | kernel | — | — |
| linux | linux_kernel | < 4.9.10 | 4.9.10 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 4.9.10-1 | 4.9.10-1 |
| linux | linux_kernel | >= 0 < 3.13.0-126.175 | 3.13.0-126.175 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3381-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux in the Linux kernel did not properly handle
empty writes to /proc/pid/attr. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2618)
石磊 discovered that the RxRPC Kerberos 5 ticket handling co
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-07-21·CVSS 5.5
CVE-2015-1350 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3358-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS. Please
note that this update changes the Linux HWE kernel to the 4.10 based
kernel from Ubuntu 17.04, superseding the 4.8 based HWE kernel from
Ubuntu 16.10.
Ben Harris discovered that the Linux kernel would strip extended privilege
attributes of files when performing a failed unprivileged system call. A
local attacker could use this to cause a denial of service. (CVE-2015-1350)
Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel
did not properly validate
Red Hat
kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)
vendor_redhat·2017-02-16·CVSS 5.5
CVE-2017-2618 [MEDIUM] CWE-193 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)
kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 due to a missing commit ( bb646cdb12e75d82258c2f2e7746d5952d3e321a ) which enabled changed system behavior.
This issue does affect Red Hat Entep
Debian
CVE-2017-2618: linux - A flaw was found in the Linux kernel's handling of clearing SELinux attributes o...
vendor_debian·2017·CVSS 5.5
CVE-2017-2618 [MEDIUM] CVE-2017-2618: linux - A flaw was found in the Linux kernel's handling of clearing SELinux attributes o...
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
Scope: local
bookworm: resolved (fixed in 4.9.10-1)
bullseye: resolved (fixed in 4.9.10-1)
forky: resolved (fixed in 4.9.10-1)
sid: resolved (fixed in 4.9.10-1)
trixie: resolved (fixed in 4.9.10-1)
GHSA
GHSA-hpw2-j46j-hpv2: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4
ghsa_unreviewed·2022-05-13
CVE-2017-2618 [MEDIUM] CWE-193 GHSA-hpw2-j46j-hpv2: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
OSV
CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4
osv·2018-07-27·CVSS 5.5
CVE-2017-2618 [MEDIUM] CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
OSV
linux vulnerabilities
osv·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux in the Linux kernel did not properly handle
empty writes to /proc/pid/attr. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2618)
石磊 discovered that the RxRPC Kerberos 5 ticket handling code in the
Linux kernel did not properly verify metadata. A remote attacker could
OSV
linux-hwe vulnerabilities
osv·2017-07-21·CVSS 5.5
[MEDIUM] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3358-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS. Please
note that this update changes the Linux HWE kernel to the 4.10 based
kernel from Ubuntu 17.04, superseding the 4.8 based HWE kernel from
Ubuntu 16.10.
Ben Harris discovered that the Linux kernel would strip extended privilege
attributes of files when performing a failed unprivileged system call. A
local attacker could use this to cause a denial of service. (CVE-2015-1350)
Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel
did not properly validate meta block groups. An attacker with physical
access could use this to specially cr
Kernel
selinux: fix off-by-one in setprocattr
kernel_security·2017-01-31·CVSS 5.5
CVE-2017-2618 [MEDIUM] selinux: fix off-by-one in setprocattr
selinux: fix off-by-one in setprocattr
SELinux tries to support setting/clearing of /proc/pid/attr attributes
from the shell by ignoring terminating newlines and treating an
attribute value that begins with a NUL or newline as an attempt to
clear the attribute. However, the test for clearing attributes has
always been wrong; it has an off-by-one error, and this could further
lead to reading past the end of the allocated buffer since commit
bb646cdb12e75d82258c2f2e7746d5952d3e321a ("proc_pid_attr_write():
switch to memdup_user()"). Fix the off-by-one error.
Even with this fix, setting and clearing /proc/pid/attr attributes
from the shell is not straightforward since the interface does not
support multiple write() calls (so shells that write the value and
newline separately will set and th
Kernel
selinux: fix off-by-one in setprocattr
kernel_security·2017-01-31·CVSS 5.5
CVE-2017-2618 [MEDIUM] selinux: fix off-by-one in setprocattr
selinux: fix off-by-one in setprocattr
SELinux tries to support setting/clearing of /proc/pid/attr attributes
from the shell by ignoring terminating newlines and treating an
attribute value that begins with a NUL or newline as an attempt to
clear the attribute. However, the test for clearing attributes has
always been wrong; it has an off-by-one error, and this could further
lead to reading past the end of the allocated buffer since commit
bb646cdb12e75d82258c2f2e7746d5952d3e321a ("proc_pid_attr_write():
switch to memdup_user()"). Fix the off-by-one error.
Even with this fix, setting and clearing /proc/pid/attr attributes
from the shell is not straightforward since the interface does not
support multiple write() calls (so shells that write the value and
newline separately will set and th
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate) [fedora-all]
bugzilla·2017-02-16·CVSS 5.5
CVE-2017-2618 [MEDIUM] CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate) [fedora-all]
CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)
bugzilla·2017-02-07·CVSS 5.5
CVE-2017-2618 [MEDIUM] CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)
CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)
A flaw was found in the Linux kernels handling of clearing SELinux attributes on /proc/pid/attr files. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
This may lead to local DoS by panicing the system.
Proposed patch:
https://git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/commit/?id=0c461cb727d146c9ef2d3e86214f498b78b7d125
https://marc.info/?l=selinux&m=148588165923772&w=2
Discussion:
To be clear, the problem is not with libselinux but the kernel itself (see the proposed patch in the original problem description).
---
(In reply to Paul Moore from comment #2)
> To be clear, the problem is not with libselinu
http://www.securityfocus.com/bid/96272https://access.redhat.com/errata/RHSA-2017:0931https://access.redhat.com/errata/RHSA-2017:0932https://access.redhat.com/errata/RHSA-2017:0933https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2618https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=0c461cb727d146c9ef2d3e86214f498b78b7d125https://marc.info/?l=selinux&m=148588165923772&w=2https://www.debian.org/security/2017/dsa-3791http://www.securityfocus.com/bid/96272https://access.redhat.com/errata/RHSA-2017:0931https://access.redhat.com/errata/RHSA-2017:0932https://access.redhat.com/errata/RHSA-2017:0933https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2618https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=0c461cb727d146c9ef2d3e86214f498b78b7d125https://marc.info/?l=selinux&m=148588165923772&w=2https://www.debian.org/security/2017/dsa-3791
2018-07-27
Published