CVE-2017-7482
published 2018-07-30CVE-2017-7482: In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.47%
37.5th percentile
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.11.11-1 (bookworm) | linux 4.11.11-1 (bookworm) |
| linux | linux_kernel | < 3.2.90 | 3.2.90 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 3.13.0-126.175 | 3.13.0-126.175 |
| linux | linux_kernel | >= 0 < 4.4.0-92.115 | 4.4.0-92.115 |
| linux | linux_kernel | >= 0 < 4.4.0-89.112 | 4.4.0-89.112 |
| linux | linux_kernel | >= 3.11 < 3.16.45 | 3.16.45 |
| linux | linux_kernel | >= 3.17 < 3.18.59 | 3.18.59 |
| linux | linux_kernel | >= 3.19 < 4.1.43 | 4.1.43 |
| linux | linux_kernel | >= 3.3 < 3.10.108 | 3.10.108 |
| linux | linux_kernel | >= 4.10 < 4.11.8 | 4.11.8 |
| linux | linux_kernel | >= 4.2 < 4.4.75 | 4.4.75 |
| linux | linux_kernel | >= 4.5 < 4.9.35 | 4.9.35 |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Xenial HWE) regression
vendor_ubuntu·2017-08-16·CVSS 7.8
[HIGH] Linux kernel (Xenial HWE) regression
Title: Linux kernel (Xenial HWE) regression
Summary: USN-3378-2 introduced a regression the Linux Hardware Enablement
kernel.
USN-3392-1 fixed a regression in the Linux kernel for Ubuntu 16.04 LTS.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS.
USN-3378-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel. Unfortunately, a regression was introduced that prevented
conntrack from working correctly in some situations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a
Ubuntu
Linux kernel regression
vendor_ubuntu·2017-08-16·CVSS 7.8
[HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: USN-3378-1 introduced a regression in the Linux kernel.
USN-3378-1 fixed vulnerabilities in the Linux kernel. Unfortunately, a
regression was introduced that prevented conntrack from working
correctly in some situations. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbi
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3381-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux in the Linux kernel did not properly handle
empty writes to /proc/pid/attr. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2618)
石磊 discovered that the RxRPC Kerberos 5 ticket handling co
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3377-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in some situations. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2017-10810)
石磊 discovered
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3378-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
Red Hat
kernel: net/rxrpc: overflow in decoding of krb5 principal
vendor_redhat·2017-06-26·CVSS 7.8
CVE-2017-7482 [HIGH] CWE-190 kernel: net/rxrpc: overflow in decoding of krb5 principal
kernel: net/rxrpc: overflow in decoding of krb5 principal
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
Keberos 5 tickets being decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5,6 and 7 as the
Debian
CVE-2017-7482: linux - In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using t...
vendor_debian·2017·CVSS 7.8
CVE-2017-7482 [HIGH] CVE-2017-7482: linux - In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using t...
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
Scope: local
bookworm: resolved (fixed in 4.11.11-1)
bullseye: resolved (fixed in 4.11.11-1)
forky: resolved (fixed in 4.11.11-1)
sid: resolved (fixed in 4.11.11-1)
trixie: resolved (fixed in 4.11.11-1)
GHSA
GHSA-2x6j-879g-gpqr: In the Linux kernel before version 4
ghsa_unreviewed·2022-05-13
CVE-2017-7482 [HIGH] CWE-190 GHSA-2x6j-879g-gpqr: In the Linux kernel before version 4
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
OSV
CVE-2017-7482: In the Linux kernel before version 4
osv·2018-07-30·CVSS 7.8
CVE-2017-7482 [HIGH] CVE-2017-7482: In the Linux kernel before version 4
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
osv·2017-08-16·CVSS 7.8
[HIGH] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
USN-3378-1 fixed vulnerabilities in the Linux kernel. Unfortunately, a
regression was introduced that prevented conntrack from working
correctly in some situations. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000
OSV
linux-lts-xenial regression
osv·2017-08-16·CVSS 7.8
[HIGH] linux-lts-xenial regression
linux-lts-xenial regression
USN-3392-1 fixed a regression in the Linux kernel for Ubuntu 16.04 LTS.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS.
USN-3378-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel. Unfortunately, a regression was introduced that prevented
conntrack from working correctly in some situations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered tha
OSV
linux vulnerabilities
osv·2017-08-07·CVSS 4.7
CVE-2016-8405 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Peter Pi discovered that the colormap handling for frame buffer devices in
the Linux kernel contained an integer overflow. A local attacker could use
this to disclose sensitive information (kernel memory). (CVE-2016-8405)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
It was discovered that SELinux in the Linux kernel did not properly handle
empty writes to /proc/pid/attr. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2618)
石磊 discovered that the RxRPC Kerberos 5 ticket handling code in the
Linux kernel did not properly verify metadata. A remote attacker could
OSV
linux-hwe vulnerabilities
osv·2017-08-03·CVSS 7.8
CVE-2017-7533 [HIGH] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3377-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in so
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-08-03·CVSS 7.8
CVE-2017-7533 [HIGH] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in some situations. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2017-10810)
石磊 discovered that the RxRPC Kerberos 5
OSV
linux-lts-xenial vulnerabilities
osv·2017-08-03·CVSS 7.8
[HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3378-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly fr
Kernel
rxrpc: Fix several cases where a padded len isn't checked in ticket decode
kernel_security·2017-06-15·CVSS 7.8
CVE-2017-7482 [HIGH] rxrpc: Fix several cases where a padded len isn't checked in ticket decode
rxrpc: Fix several cases where a padded len isn't checked in ticket decode
This fixes CVE-2017-7482.
When a kerberos 5 ticket is being decoded so that it can be loaded into an
rxrpc-type key, there are several places in which the length of a
variable-length field is checked to make sure that it's not going to
overrun the available data - but the data is padded to the nearest
four-byte boundary and the code doesn't check for this extra. This could
lead to the size-remaining variable wrapping and the data pointer going
over the end of the buffer.
Fix this by making the various variable-length data checks use the padded
length.
Reported-by: 石磊
Signed-off-by: David Howells
Reviewed-by: Marc Dionne
Reviewed-by: Dan Carpenter
Signed-off-by: David S. Miller
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7482 kernel: net/rxrpc: overflow in decoding of krb5 principal [fedora-all]
bugzilla·2017-06-26·CVSS 7.8
CVE-2017-7482 [HIGH] CVE-2017-7482 kernel: net/rxrpc: overflow in decoding of krb5 principal [fedora-all]
CVE-2017-7482 kernel: net/rxrpc: overflow in decoding of krb5 principal [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2017-7482 kernel: net/rxrpc: overflow in decoding of krb5 principal
bugzilla·2017-04-27·CVSS 7.8
CVE-2017-7482 [HIGH] CVE-2017-7482 kernel: net/rxrpc: overflow in decoding of krb5 principal
CVE-2017-7482 kernel: net/rxrpc: overflow in decoding of krb5 principal
When a kerberos 5 ticket is being decoded so that it can be loaded into an rxrpc-type key, the length of a variable-length field is checked to make sure that it's not going to overrun the allocated buffer space.
The data is padded to the nearest four-byte boundary and the code doesn't check for this extra four-byte aligned padding. This can lead to the size-remaining variable wrapping and the data pointer accessing or reading past the end of the buffer. The read functionality could allow for a 3 byte infoleak and the write flaw could allow for an uncontrolled 3 byte write to kernels slab memory. This could lead to memory corruption and possible privilege escalation although no known exploit exists at the time of writ
http://seclists.org/oss-sec/2017/q2/602http://www.securityfocus.com/bid/99299http://www.securitytracker.com/id/1038787https://access.redhat.com/errata/RHSA-2019:0641https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7482https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5f2f97656ada8d811d3c1bef503ced266fcd53a0https://www.debian.org/security/2017/dsa-3927https://www.debian.org/security/2017/dsa-3945http://seclists.org/oss-sec/2017/q2/602http://www.securityfocus.com/bid/99299http://www.securitytracker.com/id/1038787https://access.redhat.com/errata/RHSA-2019:0641https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7482https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5f2f97656ada8d811d3c1bef503ced266fcd53a0https://www.debian.org/security/2017/dsa-3927https://www.debian.org/security/2017/dsa-3945
2018-07-30
Published