CVE-2017-7184
published 2017-03-19CVE-2017-7184: The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.80%
76.3th percentile
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.9.18-1 (bookworm) | linux 4.9.18-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 3.2.89 | 3.2.89 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.9.18-1 | 4.9.18-1 |
| linux | linux_kernel | >= 0 < 4.9.18-1 | 4.9.18-1 |
| linux | linux_kernel | >= 0 < 4.9.18-1 | 4.9.18-1 |
| linux | linux_kernel | >= 0 < 4.9.18-1 | 4.9.18-1 |
| linux | linux_kernel | >= 3.11 < 3.12.73 | 3.12.73 |
| linux | linux_kernel | >= 3.13 < 3.16.44 | 3.16.44 |
| linux | linux_kernel | >= 3.17 < 3.18.49 | 3.18.49 |
| linux | linux_kernel | >= 3.19 < 4.1.49 | 4.1.49 |
| linux | linux_kernel | >= 3.3 < 3.10.106 | 3.10.106 |
| linux | linux_kernel | >= 4.10 < 4.10.8 | 4.10.8 |
| linux | linux_kernel | >= 4.2 < 4.4.59 | 4.4.59 |
| linux | linux_kernel | >= 4.5 < 4.9.20 | 4.9.20 |
| ubuntu | linux | — | — |
| ubuntu | linux-raspi2 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Mobile Industrial Robots Vehicles and MiR Fleet Software
cisa_ics·2021-10-07·CVSS 7.8
[HIGH] Mobile Industrial Robots Vehicles and MiR Fleet Software
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mobile Industrial Robots Vehicles and MiR Fleet Software
Last RevisedOctober 07, 2021
Alert CodeICSA-21-280-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Mobile Industrial Robots (MiR)
- Equipment: MiR100, MiR200, MiR250, MiR500, MiR1000, MiR Fleet
- Vulnerabilities: Improper Access Control, Integer Overflow or Wraparound, Exposure of Resource to Wrong Sphere, Missing Authentication for Critical Function, Missing Encryption of Sensitive Data, Exposure of Sensitive Information to an Una
Android
CVE-2017-7184: Android Security Bulletin 2017-05-01
CVE: CVE-2017-7184
Severity: HIGH
References: A-36565222
Upstream kernel
[2]
vendor_android·2017-05-01·CVSS 7.8
CVE-2017-7184 [HIGH] CVE-2017-7184: Android Security Bulletin 2017-05-01
CVE: CVE-2017-7184
Severity: HIGH
References: A-36565222
Upstream kernel
[2]
Android Security Bulletin 2017-05-01
CVE: CVE-2017-7184
Severity: HIGH
References: A-36565222
Upstream kernel
[2]
Ubuntu
Linux kernel (HWE) vulnerability
vendor_ubuntu·2017-03-30
CVE-2017-7184 Linux kernel (HWE) vulnerability
Title: Linux kernel (HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
USN-3251-1 fixed a vulnerability in the Linux kernel for Ubuntu 16.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.10 for Ubuntu 16.04 LTS.
It was discovered that the xfrm framework for transforming packets in the
Linux kernel did not properly validate data received from user space. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code with administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given
Ubuntu
Linux kernel (Xenial HWE) vulnerability
vendor_ubuntu·2017-03-30
CVE-2017-7184 Linux kernel (Xenial HWE) vulnerability
Title: Linux kernel (Xenial HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
USN-3249-1 fixed a vulnerability in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the xfrm framework for transforming packets in the
Linux kernel did not properly validate data received from user space. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code with administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates h
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2017-03-29
CVE-2017-7184 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that the xfrm framework for transforming packets in the
Linux kernel did not properly validate data received from user space. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code with administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, l
Red Hat
kernel: Out-of-bounds heap access in xfrm
vendor_redhat·2017-03-29·CVSS 7.8
CVE-2017-7184 [HIGH] CWE-122 kernel: Out-of-bounds heap access in xfrm
kernel: Out-of-bounds heap access in xfrm
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
Out-of-bounds kernel heap access vulnerability was found in xfrm, kernel's IP framework for transforming packets. An error dealing with netlink messages from an unprivileged user leads to arbitrary read/write and privilege escalation.
Statement: This issue does not affect the Linux kernel packages as shipped with
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2017-03-29
CVE-2017-7184 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
USN-3250-1 fixed a vulnerability in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that the xfrm framework for transforming packets in the
Linux kernel did not properly validate data received from user space. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code with administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates h
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2017-03-29
CVE-2017-7184 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that the xfrm framework for transforming packets in the
Linux kernel did not properly validate data received from user space. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code with administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, l
Debian
CVE-2017-7184: linux - The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel ...
vendor_debian·2017·CVSS 7.8
CVE-2017-7184 [HIGH] CVE-2017-7184: linux - The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel ...
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
Scope: local
bookworm: resolved (fixed in 4.9.18-1)
bullseye: resolved (fixed in 4.9.18-1)
forky: resolved (fixed in 4.9.18-1)
sid: resolved (fixed in 4.9.18-1)
trixie: resolved (fixed in 4.9.18-1)
GHSA
GHSA-hxjx-r7gc-4xhx: The xfrm_replay_verify_len function in net/xfrm/xfrm_user
ghsa_unreviewed·2022-05-13
CVE-2017-7184 [HIGH] GHSA-hxjx-r7gc-4xhx: The xfrm_replay_verify_len function in net/xfrm/xfrm_user
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
Project0
Exploiting the Linux kernel via packet sockets - Project Zero
project_zero·2017-05-01·CVSS 7.8
CVE-2016-8655 [HIGH] Exploiting the Linux kernel via packet sockets - Project Zero
Guest blog post, posted by Andrey Konovalov
Introduction
Lately I’ve been spending some time fuzzing network-related Linux kernel interfaces with syzkaller. Besides the recently discovered vulnerability in DCCP sockets, I also found another one, this time in packet sockets. This post describes how the bug was discovered and how we can exploit it to escalate privileges.
The bug itself (CVE-2017-7308) is a signedness issue, which leads to an exploitable heap-out-of-bounds write. It can be triggered by providing specific parameters to the PACKET_RX_RING option on an AF_PACKET socket with a TPACKET_V3 ring buffer version enabled. As a result the following sanity check in the packet_set_ring() function in net/packet/af_packet.c can be bypassed, which later leads to an out-of-bounds access.
Kernel
xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder
kernel_security·2017-03-23·CVSS 7.8
CVE-2017-7184 [HIGH] xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder
xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder
Kees Cook has pointed out that xfrm_replay_state_esn_len() is subject to
wrapping issues. To ensure we are correctly ensuring that the two ESN
structures are the same size compare both the overall size as reported
by xfrm_replay_state_esn_len() and the internal length are the same.
CVE-2017-7184
Signed-off-by: Andy Whitcroft
Acked-by: Steffen Klassert
Signed-off-by: Linus Torvalds
Kernel
xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window
kernel_security·2017-03-22·CVSS 7.8
CVE-2017-7184 [HIGH] xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window
xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window
When a new xfrm state is created during an XFRM_MSG_NEWSA call we
validate the user supplied replay_esn to ensure that the size is valid
and to ensure that the replay_window size is within the allocated
buffer. However later it is possible to update this replay_esn via a
XFRM_MSG_NEWAE call. There we again validate the size of the supplied
buffer matches the existing state and if so inject the contents. We do
not at this point check that the replay_window is within the allocated
memory. This leads to out-of-bounds reads and writes triggered by
netlink packets. This leads to memory corruption and the potential for
priviledge escalation.
We already attempt to validate the incoming replay information in
xfrm_new_ae() via
OSV
CVE-2017-7184: The xfrm_replay_verify_len function in net/xfrm/xfrm_user
osv·2017-03-19·CVSS 7.8
CVE-2017-7184 [HIGH] CVE-2017-7184: The xfrm_replay_verify_len function in net/xfrm/xfrm_user
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15908 systemd: Infinite loop in the dns_packet_read_type_window() function
bugzilla·2017-10-30·CVSS 7.5
CVE-2017-15908 [HIGH] CVE-2017-15908 systemd: Infinite loop in the dns_packet_read_type_window() function
CVE-2017-15908 systemd: Infinite loop in the dns_packet_read_type_window() function
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.
References:
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351
Upstream pull request:
https://github.com/systemd/systemd/pull/7184
Upstream patch:
https://github.com/systemd/systemd/commit/8aeadf3052a2130b88d5bccf5439890e1034f28d
Discussion:
Statement:
This issue did not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.
Bugzilla
CVE-2017-7184 kernel: Out-of-bounds heap access in xfrm [fedora-all]
bugzilla·2017-03-30·CVSS 7.8
CVE-2017-7184 [HIGH] CVE-2017-7184 kernel: Out-of-bounds heap access in xfrm [fedora-all]
CVE-2017-7184 kernel: Out-of-bounds heap access in xfrm [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2017-7184 kernel: Out-of-bounds heap access in xfrm
bugzilla·2017-03-23·CVSS 7.8
CVE-2017-7184 [HIGH] CVE-2017-7184 kernel: Out-of-bounds heap access in xfrm
CVE-2017-7184 kernel: Out-of-bounds heap access in xfrm
Out-of-bounds kernel heap access vulnerability was found in xfrm, kernel's IP framework for transforming packets. An error dealing with netlink messages from unprivileged user leads to arbitrary read/write and privilege escalation.
Public disclosure on oss-security:
http://openwall.com/lists/oss-security/2017/03/29/2
http://seclists.org/oss-sec/2017/q1/689
Upstream patches:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=677e806da4d916052585301785d847c3b3e6186a
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f843ee6dd019bcece3e74e76ad9df0155655d0df
Discussion:
Created attachment 1265661
Proposed patch
---
Acknowledgments:
Name: Chaitin Security Research Lab
---
arXiv
Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems
arxiv_fulltext·2024-09-07
Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems
Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems
Jinmeng Zhou, Jiayi Hu, Ziyue Pan, Jiaxun Zhu, Wenbo Shen, Guoren Li, Zhiyun Qian
Jinmeng Zhou, Jiayi Hu, Ziyue Pan, Jiaxun Zhu and Wenbo Shen are with the College of Computer Science and Technology at Zhejiang University, Hangzhou, Zhejiang, 310027, China.
Email: \jinmengzhou, hujiayi, ziyuepan, sevenswords, shenwenbo\@zju.edu.cn;
Guoren Li and Zhiyun Qian are with the Department of Computer Science and Engineering, University of California, Riverside 92521, USA.
Email: [email protected] and [email protected];
Wenbo Shen is the corresponding author.
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, VOL. XX, 20XX
Shell et al.: A Sample Article Using IEEEtran.cls for IEEE Journals
## Abstra
arXiv
On the Effectiveness of Type-based Control Flow Integrity
arxiv_fulltext·2020-02-14
On the Effectiveness of Type-based Control Flow Integrity
2018
2018
acmcopyright
[ACSAC '18]2018 Annual Computer Security Applications ConferenceDecember 3--7, 2018San Juan, PR, USA
2018 Annual Computer Security Applications Conference (ACSAC '18), December 3--7, 2018, San Juan, PR, USA
15.00
10.1145/3274694.3274739
978-1-4503-6569-7/18/12
On the Effectiveness of Type-based Control Flow Integrity
Reza Mirzazade farkhani
Northeastern University
[email protected]
Saman Jafari
Northeastern University
[email protected]
Sajjad Arshad
Northeastern University
[email protected]
William Robertson
Northeastern University
[email protected]
Engin Kirda
Northeastern University
[email protected]
Hamed Okhravi
MIT Lincoln Laboratory
[email protected]
## Abstract
Control flow integrity (CFI) has received significant attention in the community
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=677e806da4d916052585301785d847c3b3e6186ahttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f843ee6dd019bcece3e74e76ad9df0155655d0dfhttp://openwall.com/lists/oss-security/2017/03/29/2http://www.eweek.com/security/ubuntu-linux-falls-on-day-1-of-pwn2own-hacking-competitionhttp://www.securityfocus.com/bid/97018http://www.securitytracker.com/id/1038166https://access.redhat.com/errata/RHSA-2017:2918https://access.redhat.com/errata/RHSA-2017:2930https://access.redhat.com/errata/RHSA-2017:2931https://access.redhat.com/errata/RHSA-2019:4159https://blog.trendmicro.com/results-pwn2own-2017-day-one/https://github.com/torvalds/linux/commit/677e806da4d916052585301785d847c3b3e6186ahttps://github.com/torvalds/linux/commit/f843ee6dd019bcece3e74e76ad9df0155655d0dfhttps://source.android.com/security/bulletin/2017-05-01https://twitter.com/thezdi/status/842126074435665920http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=677e806da4d916052585301785d847c3b3e6186ahttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f843ee6dd019bcece3e74e76ad9df0155655d0dfhttp://openwall.com/lists/oss-security/2017/03/29/2http://www.eweek.com/security/ubuntu-linux-falls-on-day-1-of-pwn2own-hacking-competitionhttp://www.securityfocus.com/bid/97018http://www.securitytracker.com/id/1038166https://access.redhat.com/errata/RHSA-2017:2918https://access.redhat.com/errata/RHSA-2017:2930https://access.redhat.com/errata/RHSA-2017:2931https://access.redhat.com/errata/RHSA-2019:4159https://blog.trendmicro.com/results-pwn2own-2017-day-one/https://github.com/torvalds/linux/commit/677e806da4d916052585301785d847c3b3e6186ahttps://github.com/torvalds/linux/commit/f843ee6dd019bcece3e74e76ad9df0155655d0dfhttps://source.android.com/security/bulletin/2017-05-01https://twitter.com/thezdi/status/842126074435665920
2017-03-19
Published