CVE-2017-2618

CWE-193CWE-68214 documents9 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 84.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 13

Description

A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Also affects: Enterprise Linux 7.0, 7.3, 7.4, 7.5, Debian Linux 8.0

Patches

🔴Vulnerability Details

6
GHSA
GHSA-hpw2-j46j-hpv2: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 42022-05-13
OSV
CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 42018-07-27
CVEList
CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 42018-07-27
OSV
linux vulnerabilities2017-08-07
Kernel
selinux: fix off-by-one in setprocattr2017-01-31

📋Vendor Advisories

5
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2017-08-07
Ubuntu
Linux kernel vulnerabilities2017-08-07
Ubuntu
Linux kernel (HWE) vulnerabilities2017-07-21
Red Hat
kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)2017-02-16
Debian
CVE-2017-2618: linux - A flaw was found in the Linux kernel's handling of clearing SELinux attributes o...2017

💬Community

2
Bugzilla
CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate) [fedora-all]2017-02-16
Bugzilla
CVE-2017-2618 kernel: Off-by-one error in selinux_setprocattr (/proc/self/attr/fscreate)2017-02-07
CVE-2017-2618 (MEDIUM CVSS 5.5) | A flaw was found in the Linux kerne | cvebase.io