CVE-2017-2636
published 2017-03-07CVE-2017-2636: Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by…
PriorityP432high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
1.02%
60.0th percentile
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 4.9.16-1 (bookworm) | linux 4.9.16-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 0 < 4.9.16-1 | 4.9.16-1 |
| linux | linux_kernel | >= 2.6.31 < 3.2.87 | 3.2.87 |
| linux | linux_kernel | >= 3.11 < 3.12.72 | 3.12.72 |
| linux | linux_kernel | >= 3.13 < 3.16.42 | 3.16.42 |
| linux | linux_kernel | >= 3.17 < 3.18.49 | 3.18.49 |
| linux | linux_kernel | >= 3.19 < 4.1.49 | 4.1.49 |
| linux | linux_kernel | >= 3.3 < 3.10.106 | 3.10.106 |
| linux | linux_kernel | >= 4.10 < 4.10.3 | 4.10.3 |
| linux | linux_kernel | >= 4.2 < 4.4.54 | 4.4.54 |
| linux | linux_kernel | >= 4.5 < 4.9.15 | 4.9.15 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (AWS) vulnerability
vendor_ubuntu·2017-03-09
CVE-2017-2636 Linux kernel (AWS) vulnerability
Title: Linux kernel (AWS) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
USN-3220-1 fixed a vulnerability in the Linux kernel. This update
provides the corresponding updates for the Linux kernel for Amazon
Web Services (AWS).
Alexander Popov discovered that the N_HDLC line discipline implementation
in the Linux kernel contained a double-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2017-03-08
CVE-2017-2636 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
USN-3219-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
Alexander Popov discovered that the N_HDLC line discipline implementation
in the Linux kernel contained a double-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new vers
Ubuntu
Linux kernel (Xenial HWE) vulnerability
vendor_ubuntu·2017-03-08
CVE-2017-2636 Linux kernel (Xenial HWE) vulnerability
Title: Linux kernel (Xenial HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
USN-3220-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Alexander Popov discovered that the N_HDLC line discipline implementation
in the Linux kernel contained a double-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new vers
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2017-03-08
CVE-2017-2636 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Alexander Popov discovered that the N_HDLC line discipline implementation
in the Linux kernel contained a double-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE,
Ubuntu
Linux kernel (HWE) vulnerability
vendor_ubuntu·2017-03-08·CVSS 7.0
CVE-2017-2636 [HIGH] Linux kernel (HWE) vulnerability
Title: Linux kernel (HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
USN-3221-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.10 for Ubuntu 16.04 LTS.
Alexander Popov discovered that the N_HDLC line discipline implementation
in the Linux kernel contained a double-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2017-2636)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new ver
Red Hat
kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release()
vendor_redhat·2017-03-07·CVSS 7.0
CVE-2017-2636 [HIGH] CWE-362 kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release()
kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release()
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
A race condition flaw was found in the N_HLDC Linux kernel driver when accessing n_hdlc.tbuf list that can lead to double free. A local, unprivileged user able to set the HDLC line discipline on the tty device could use this flaw to increase their privileges on the system.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2. As this issue
Debian
CVE-2017-2636: linux - Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows...
vendor_debian·2017·CVSS 7.0
CVE-2017-2636 [HIGH] CVE-2017-2636: linux - Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows...
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
Scope: local
bookworm: resolved (fixed in 4.9.16-1)
bullseye: resolved (fixed in 4.9.16-1)
forky: resolved (fixed in 4.9.16-1)
sid: resolved (fixed in 4.9.16-1)
trixie: resolved (fixed in 4.9.16-1)
GHSA
GHSA-gxfh-c6q2-wcm7: Race condition in drivers/tty/n_hdlc
ghsa_unreviewed·2022-05-14
CVE-2017-2636 [HIGH] CWE-362 GHSA-gxfh-c6q2-wcm7: Race condition in drivers/tty/n_hdlc
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
Kernel
mm/slub.c: add a naive detection of double free or corruption
kernel_security·2017-09-06·CVSS 7.0
CVE-2017-2636 [HIGH] mm/slub.c: add a naive detection of double free or corruption
mm/slub.c: add a naive detection of double free or corruption
Add an assertion similar to "fasttop" check in GNU C Library allocator
as a part of SLAB_FREELIST_HARDENED feature. An object added to a
singly linked freelist should not point to itself. That helps to detect
some double free errors (e.g. CVE-2017-2636) without slub_debug and
KASAN.
Link: http://lkml.kernel.org/r/[email protected]
Signed-off-by: Alexander Popov
Acked-by: Christoph Lameter
Cc: Kees Cook
Cc: Pekka Enberg
Cc: David Rientjes
Cc: Joonsoo Kim
Cc: Paul E McKenney
Cc: Ingo Molnar
Cc: Tejun Heo
Cc: Andy Lutomirski
Cc: Nicolas Pitre
Cc: Rik van Riel
Cc: Tycho Andersen
Signed-off-by: Andrew Morton
Signed-off-by: Linus Torvalds
OSV
linux-hwe vulnerability
osv·2017-03-08·CVSS 7.0
CVE-2017-2636 [HIGH] linux-hwe vulnerability
linux-hwe vulnerability
USN-3221-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.10 for Ubuntu 16.04 LTS.
Alexander Popov discovered that the N_HDLC line discipline implementation
in the Linux kernel contained a double-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2017-2636)
OSV
CVE-2017-2636: Race condition in drivers/tty/n_hdlc
osv·2017-03-07·CVSS 7.0
CVE-2017-2636 [HIGH] CVE-2017-2636: Race condition in drivers/tty/n_hdlc
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2636 kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release() [fedora-all]
bugzilla·2017-03-07·CVSS 7.0
CVE-2017-2636 [HIGH] CVE-2017-2636 kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release() [fedora-all]
CVE-2017-2636 kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2017-2636 kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release()
bugzilla·2017-03-02·CVSS 7.0
CVE-2017-2636 [HIGH] CVE-2017-2636 kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release()
CVE-2017-2636 kernel: Race condition access to n_hdlc.tbuf causes double free in n_hdlc_release()
A race condition flaw was found in the N_HLDC Linux kernel driver when accessing n_hdlc.tbuf that can lead to double free.
A local, unprivileged user able to set the HDLC line discipline on the tty device could use this flaw to increase their privileges on the system.
Discussion:
Acknowledgments:
Name: Alexander Popov
---
Mitigation:
The n_hdlc kernel module will be automatically loaded when an application attempts to use the HDLC line discipline from userspace. This module can be prevented from being loaded by using the system-wide modprobe rules. The following command, run as root, will prevent accidental or intentional loading of the module. Red Hat Product Security believe this met
http://www.debian.org/security/2017/dsa-3804http://www.openwall.com/lists/oss-security/2017/03/07/6http://www.securityfocus.com/bid/96732http://www.securitytracker.com/id/1037963https://a13xp0p0v.github.io/2017/03/24/CVE-2017-2636.htmlhttps://access.redhat.com/errata/RHSA-2017:0892https://access.redhat.com/errata/RHSA-2017:0931https://access.redhat.com/errata/RHSA-2017:0932https://access.redhat.com/errata/RHSA-2017:0933https://access.redhat.com/errata/RHSA-2017:0986https://access.redhat.com/errata/RHSA-2017:1125https://access.redhat.com/errata/RHSA-2017:1126https://access.redhat.com/errata/RHSA-2017:1232https://access.redhat.com/errata/RHSA-2017:1233https://access.redhat.com/errata/RHSA-2017:1488https://bugzilla.redhat.com/show_bug.cgi?id=1428319http://www.debian.org/security/2017/dsa-3804http://www.openwall.com/lists/oss-security/2017/03/07/6http://www.securityfocus.com/bid/96732http://www.securitytracker.com/id/1037963https://a13xp0p0v.github.io/2017/03/24/CVE-2017-2636.htmlhttps://access.redhat.com/errata/RHSA-2017:0892https://access.redhat.com/errata/RHSA-2017:0931https://access.redhat.com/errata/RHSA-2017:0932https://access.redhat.com/errata/RHSA-2017:0933https://access.redhat.com/errata/RHSA-2017:0986https://access.redhat.com/errata/RHSA-2017:1125https://access.redhat.com/errata/RHSA-2017:1126https://access.redhat.com/errata/RHSA-2017:1232https://access.redhat.com/errata/RHSA-2017:1233https://access.redhat.com/errata/RHSA-2017:1488https://bugzilla.redhat.com/show_bug.cgi?id=1428319
2017-03-07
Published