Updated: 2023-12-06
CWE: Unspecified
Description:
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
CVSS3: 7.8
OS | Vendor version | Errata |
---|---|---|
RHEL 7 | 3.10.0-693.5.2.el7 | RHSA-2017:2930 |
Ubuntu 16.04 | 4.4.0-71.92 | USN-3249-1 |
Ubuntu 14.04 | 3.13.0-115.162 | USN-3250-1 |
Ubuntu 14.04 HWE | 4.4.0-71.92~14.04.1 | USN-3249-2 |
CentOS 7 | 3.10.0-693.5.2.el7 | CESA-2017:2930 |
CentOS 7 plus | 3.10.0-693.5.2.el7.centos.plus | CESA-2017:2930 |
Oracle Linux 7 | 3.10.0-693.5.2.0.1.el7 | ELSA-2017-2930-1 |
OS | Original kernel version | State |
---|---|---|
RHEL 7 |
3.10.0-514.6.1.el7
show all
hide all
3.10.0-693.el7
3.10.0-123.8.1.el7
3.10.0-123.13.1.el7
3.10.0-693.2.2.el7
3.10.0-514.21.2.el7
3.10.0-229.el7
3.10.0-327.18.2.el7
3.10.0-123.6.3.el7
3.10.0-123.13.2.el7
3.10.0-229.14.1.el7
3.10.0-123.20.1.el7
3.10.0-514.21.1.el7
3.10.0-327.4.5.el7
3.10.0-123.4.2.el7
3.10.0-327.3.1.el7
3.10.0-327.36.3.el7
3.10.0-693.1.1.el7
3.10.0-123.1.2.el7
3.10.0-327.36.2.el7
3.10.0-514.10.2.el7
3.10.0-514.26.1.el7
3.10.0-123.9.2.el7
3.10.0-327.36.1.el7
3.10.0-123.el7
3.10.0-514.2.2.el7
3.10.0-693.2.1.el7
3.10.0-123.9.3.el7
3.10.0-327.13.1.el7
3.10.0-327.4.4.el7
3.10.0-514.26.2.el7
3.10.0-123.4.4.el7
3.10.0-327.22.2.el7
3.10.0-229.4.2.el7
3.10.0-327.28.2.el7
3.10.0-229.7.2.el7
3.10.0-327.10.1.el7
3.10.0-327.el7
3.10.0-327.28.3.el7
3.10.0-229.11.1.el7
3.10.0-229.20.1.el7
3.10.0-229.1.2.el7
3.10.0-514.el7
3.10.0-514.16.1.el7
3.10.0-514.6.2.el7
|
Released |
Ubuntu 16.04 |
4.4.0-21.37
show all
hide all
4.4.0-65.86
4.4.0-70.91
4.4.0-64.85
4.4.0-34.53
4.4.0-22.40
4.4.0-62.83
4.4.0-31.50
4.4.0-28.47
4.4.0-63.84
4.4.0-47.68
4.4.0-24.43
4.4.0-38.57
4.4.0-67.88
4.4.0-22.39
4.4.0-42.62
4.4.0-51.72
4.4.0-53.74
4.4.0-36.55
4.4.0-23.41
4.4.0-43.63
4.4.0-66.87
4.4.0-45.66
4.4.0-57.78
4.4.0-59.80
|
Released |
Ubuntu 14.04 |
3.13.0-109.156
show all
hide all
3.13.0-111.158
3.13.0-38.65
3.13.0-53.88
3.13.0-39.66
3.13.0-65.106
3.13.0-57.95
3.13.0-92.139
3.13.0-96.143
3.13.0-37.64
3.13.0-95.142
3.13.0-49.83
3.13.0-68.111
3.13.0-59.98
3.13.0-101.148
3.13.0-100.147
3.13.0-71.114
3.13.0-86.130
3.13.0-91.138
3.13.0-107.154
3.13.0-67.110
3.13.0-70.113
3.13.0-76.120
3.13.0-106.153
3.13.0-41.70
3.13.0-36.63
3.13.0-44.73
3.13.0-49.81
3.13.0-86.131
3.13.0-85.129
3.13.0-46.75
3.13.0-112.159
3.13.0-40.69
3.13.0-98.145
3.13.0-108.155
3.13.0-33.58
3.13.0-110.157
3.13.0-105.152
3.13.0-73.116
3.13.0-43.72
3.13.0-51.84
3.13.0-62.102
3.13.0-83.127
3.13.0-54.91
3.13.0-45.74
3.13.0-46.77
3.13.0-53.87
3.13.0-55.94
3.13.0-62.101
3.13.0-64.104
3.13.0-66.107
3.13.0-113.160
3.13.0-40.68
3.13.0-46.76
3.13.0-52.86
3.13.0-61.100
3.13.0-69.112
3.13.0-72.115
3.13.0-75.119
3.13.0-65.105
3.13.0-77.121
3.13.0-58.97
3.13.0-32.57
3.13.0-46.79
3.13.0-74.118
3.13.0-52.85
3.13.0-34.60
3.13.0-35.62
3.13.0-48.80
3.13.0-87.133
3.13.0-93.140
3.13.0-66.108
3.13.0-103.150
3.13.0-63.103
3.13.0-88.135
3.13.0-55.92
3.13.0-53.89
3.13.0-79.123
|
Released |
Ubuntu 14.04 HWE |
4.4.0-70.91~14.04.1
show all
hide all
4.4.0-34.53~14.04.1
4.4.0-51.72~14.04.1
4.4.0-63.84~14.04.2
4.4.0-66.87~14.04.1
4.4.0-53.74~14.04.1
4.4.0-28.47~14.04.1
4.4.0-57.78~14.04.1
4.4.0-62.83~14.04.1
4.4.0-64.85~14.04.1
4.4.0-24.43~14.04.1
4.4.0-47.68~14.04.1
4.4.0-31.50~14.04.1
4.4.0-42.62~14.04.1
4.4.0-38.57~14.04.1
4.4.0-22.40~14.04.1
4.4.0-21.37~14.04.1
4.4.0-23.41~14.04.1
4.4.0-65.86~14.04.1
4.4.0-36.55~14.04.1
4.4.0-59.80~14.04.1
4.4.0-67.88~14.04.1
4.4.0-45.66~14.04.1
4.4.0-22.39~14.04.1
|
Released |
Debian 8 |
3.16.7-ckt11-1+deb8u1
show all
hide all
3.16.7-ckt9-3~deb8u1
3.16.39-1+deb8u2
3.16.7-ckt11-1+deb8u2
3.16.7-ckt20-1+deb8u2
3.16.7-ckt11-1+deb8u3
3.16.7-ckt20-1+deb8u4
3.16.7-ckt25-2+deb8u2
3.16.36-1+deb8u2
3.16.7-ckt25-1
3.16.7-ckt11-1+deb8u4
3.16.7-ckt25-2
3.16.7-ckt11-1+deb8u5
3.16.7-ckt20-1+deb8u3
3.16.39-1
3.16.7-ckt11-1+deb8u6
3.16.7-ckt25-2+deb8u1
3.16.39-1+deb8u1
3.16.7-ckt25-2+deb8u3
3.16.7-ckt11-1
3.16.36-1+deb8u1
3.16.7-ckt20-1+deb8u1
|
Released |
CentOS 7 |
3.10.0-327.3.1.el7
show all
hide all
3.10.0-229.7.2.el7
3.10.0-327.36.3.el7
3.10.0-327.36.2.el7
3.10.0-229.11.1.el7
3.10.0-229.el7
3.10.0-123.1.2.el7
3.10.0-693.1.1.el7
3.10.0-123.4.2.el7
3.10.0-514.10.2.el7
3.10.0-123.6.3.el7
3.10.0-327.10.1.el7
3.10.0-327.28.2.el7
3.10.0-123.13.1.el7
3.10.0-123.8.1.el7
3.10.0-123.9.2.el7
3.10.0-514.21.2.el7
3.10.0-514.6.2.el7
3.10.0-229.4.2.el7
3.10.0-327.el7
3.10.0-327.22.2.el7
3.10.0-123.13.2.el7
3.10.0-327.18.2.el7
3.10.0-514.6.1.el7
3.10.0-229.14.1.el7
3.10.0-514.21.1.el7
3.10.0-514.16.1.el7
3.10.0-693.2.2.el7
3.10.0-123.9.3.el7
3.10.0-123.el7
3.10.0-327.13.1.el7
3.10.0-327.4.4.el7
3.10.0-514.2.2.el7
3.10.0-514.26.2.el7
3.10.0-693.2.1.el7
3.10.0-229.20.1.el7
3.10.0-229.1.2.el7
3.10.0-123.4.4.el7
3.10.0-693.el7
3.10.0-327.28.3.el7
3.10.0-327.36.1.el7
3.10.0-514.26.1.el7
3.10.0-514.el7
3.10.0-327.4.5.el7
3.10.0-123.20.1.el7
|
Released |
CentOS 7 plus |
3.10.0-123.8.1.el7.centos.plus
show all
hide all
3.10.0-123.6.3.el7.centos.plus
3.10.0-229.14.1.el7.centos.plus
3.10.0-327.28.2.el7.centos.plus
3.10.0-693.1.1.el7.centos.plus
3.10.0-327.36.3.el7.centos.plus
3.10.0-514.10.2.el7.centos.plus
3.10.0-123.4.4.el7.centos.plus
3.10.0-693.el7.centos.plus
3.10.0-123.13.2.el7.centos.plus
3.10.0-229.7.2.el7.centos.plus
3.10.0-123.9.2.el7.centos.plus
3.10.0-327.22.2.el7.centos.plus
3.10.0-327.36.2.el7.centos.plus
3.10.0-229.el7.centos.plus
3.10.0-123.20.1.el7.centos.plus
3.10.0-123.13.1.el7.centos.plus
3.10.0-514.el7.centos.plus
3.10.0-327.10.1.el7.centos.plus
3.10.0-327.28.3.el7.centos.plus
3.10.0-229.4.2.el7.centos.plus
3.10.0-514.6.1.el7.centos.plus
3.10.0-229.1.2.el7.centos.plus
3.10.0-514.16.1.el7.centos.plus
3.10.0-123.9.3.el7.centos.plus
3.10.0-123.el7.centos.plus
3.10.0-327.13.1.el7.centos.plus
3.10.0-693.2.1.el7.centos.plus
3.10.0-327.4.4.el7.centos.plus
3.10.0-514.2.2.el7.centos.plus
3.10.0-514.26.2.el7.centos.plus
3.10.0-123.1.2.el7.centos.plus
3.10.0-514.21.2.el7.centos.plus
3.10.0-693.2.2.el7.centos.plus
3.10.0-327.18.2.el7.centos.plus
3.10.0-229.11.1.el7.centos.plus
3.10.0-123.4.2.el7.centos.plus
3.10.0-229.20.1.el7.centos.plus
3.10.0-327.36.1.el7.centos.plus
3.10.0-327.el7.centos.plus
3.10.0-327.3.1.el7.centos.plus
3.10.0-514.6.2.el7.centos.plus
3.10.0-327.4.5.el7.centos.plus
3.10.0-514.21.1.el7.centos.plus
|
Released |
Oracle Linux 7 |
3.10.0-229.7.2.el7
show all
hide all
3.10.0-229.1.2.el7
3.10.0-123.20.1.el7
3.10.0-123.13.1.el7
3.10.0-229.4.2.el7
3.10.0-123.13.2.el7
3.10.0-123.4.4.el7
3.10.0-229.el7
3.10.0-327.4.5.el7
3.10.0-123.6.3.el7
3.10.0-327.36.3.el7
3.10.0-229.11.1.el7
3.10.0-123.4.2.el7
3.10.0-327.18.2.el7
3.10.0-327.36.2.el7
3.10.0-327.28.3.el7
3.10.0-327.3.1.el7
3.10.0-327.10.1.el7
3.10.0-514.el7
3.10.0-123.9.3.el7
3.10.0-123.el7
3.10.0-327.13.1.el7
3.10.0-327.4.4.el7
3.10.0-514.10.2.el7
3.10.0-514.16.1.el7
3.10.0-514.2.2.el7
3.10.0-514.21.1.el7
3.10.0-514.21.2.el7
3.10.0-514.26.1.el7
3.10.0-514.26.2.el7
3.10.0-514.6.2.el7
3.10.0-693.1.1.el7
3.10.0-693.2.1.el7
3.10.0-693.2.2.el7
3.10.0-693.el7
3.10.0-327.22.2.el7
3.10.0-327.28.2.el7
3.10.0-229.14.1.el7
3.10.0-123.8.1.el7
3.10.0-327.el7
3.10.0-514.6.1.el7
3.10.0-123.9.2.el7
3.10.0-229.20.1.el7
3.10.0-327.36.1.el7
3.10.0-123.1.2.el7
|
Released |
CloudLinux OS 7 |
3.10.0-427.36.1.lve1.4.40.el7
show all
hide all
3.10.0-427.36.1.lve1.4.39.el7
3.10.0-233.1.2.lve1.3.33.4.el7
3.10.0-427.18.2.lve1.4.24.el7
3.10.0-329.7.2.lve1.3.58.el7
3.10.0-223.1.2.lve1.3.33.3.el7
3.10.0-223.1.2.lve1.3.33.el7
3.10.0-233.1.2.lve1.3.33.1.el7
3.10.0-329.7.2.lve1.3.50.el7
3.10.0-329.7.2.lve1.3.55.el7
3.10.0-329.7.2.lve1.4.2.el7
3.10.0-427.10.1.lve1.4.22.el7
3.10.0-427.18.2.lve1.4.27.el7
3.10.0-427.18.2.lve1.4.38.el7
3.10.0-427.36.1.lve1.4.37.el7
3.10.0-223.1.2.lve1.3.22.el7
3.10.0-427.10.1.lve1.4.19.el7
3.10.0-427.36.1.lve1.4.43.el7
3.10.0-427.10.1.lve1.4.7.el7
3.10.0-329.7.2.lve1.4.4.el7
|
Released |
CloudLinux OS 6h |
3.10.0-427.18.2.lve1.4.24.el6h
show all
hide all
3.10.0-427.18.2.lve1.4.27.el6h
3.10.0-427.18.2.lve1.4.38.el6h
3.10.0-427.36.1.lve1.4.32.el6h
3.10.0-427.36.1.lve1.4.37.el6h
3.10.0-427.36.1.lve1.4.39.el6h
3.10.0-427.36.1.lve1.4.40.el6h
3.10.0-427.36.1.lve1.4.43.el6h
|
Released |
CentOS 6 alt |
3.18.21-17.el6
show all
hide all
3.18.25-18.el6
3.18.25-19.el6
3.18.30-20.el6
3.18.32-20.el6
3.18.34-20.el6
3.18.41-20.el6
3.18.44-20.el6
4.9.11-22.el6
4.9.13-22.el6
4.9.15-22.el6
3.18.21-16.el6
|
Released |
CentOS 7 alt |
3.18.21-16.el7
show all
hide all
3.18.21-17.el7
3.18.25-18.el7
3.18.25-19.el7
3.18.30-20.el7
3.18.32-20.el7
3.18.34-20.el7
3.18.41-20.el7
3.18.44-20.el7
4.9.11-22.el7
4.9.15-22.el7
4.9.13-22.el7
|
Released |
Endurance 6 elrepo | |
Ready For Release |
OEL 7 Dell | |
Ready For Release |
Endurance 7 eig 3.10 | |
Ready For Release |
Debian 10 cloud | |
Will Not Fix |
Debian 9 backports | |
Will Not Fix |