漏洞描述
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
access.redhat.comhttps://access.redhat.com/errata/RHSA-2017:1297↗patchwork.ozlabs.orghttps://patchwork.ozlabs.org/patch/744811/↗patchwork.ozlabs.orghttps://patchwork.ozlabs.org/patch/744813/↗access.redhat.comhttps://access.redhat.com/errata/RHSA-2017:1308↗source.android.comhttps://source.android.com/security/bulletin/2017-07-01↗access.redhat.comhttps://access.redhat.com/errata/RHSA-2017:1298↗access.redhat.comhttps://access.redhat.com/errata/RHSA-2018:1854↗patchwork.ozlabs.orghttps://patchwork.ozlabs.org/patch/744812/↗www.securityfocus.comhttp://www.securityfocus.com/bid/97234↗