Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-7558

CWE-125Out-of-bounds Read10 documents9 sources
Severity
7.5HIGH
EPSS
0.8%
top 26.51%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 26
Latest updateMay 13

Description

A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used to export socket's diagnostic information. As a result, up to 100 bytes of the slab data could be leaked to a userspace.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 1.4 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel4.74.13+1
CVEListV5linux/kernel4.7-rc1 through 4.13
Debianlinux< 4.12.13-1+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-5vf3-w6cv-wf86: A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions p2022-05-13
CVEList
CVE-2017-7558: A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions p2018-07-26
OSV
CVE-2017-7558: A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions p2018-07-26
Kernel
sctp: Avoid out-of-bounds reads from address storage2017-08-23

💥Exploits & PoCs

1
Exploit-DB
Linux Kernel 4.8 (Ubuntu 16.04) - Leak sctp Kernel Pointer2018-11-30

📋Vendor Advisories

2
Red Hat
kernel: Out of bounds read in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() in SCTP stack2017-08-23
Debian
CVE-2017-7558: linux - A kernel data leak due to an out-of-bound read was found in the Linux kernel in ...2017

💬Community

2
Bugzilla
CVE-2017-7558 kernel: Out of bounds read in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() in SCTP stack [fedora-all]2017-08-24
Bugzilla
CVE-2017-7558 kernel: Out of bounds read in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() in SCTP stack2017-08-10
CVE-2017-7558 (HIGH CVSS 7.5) | A kernel data leak due to an out-of | cvebase.io