CVE-2017-7308
CVE-2017-7308
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
Affected products
n/a · n/apublic PoCs found — 6
githubgithub.com/anldori/CVE-2017-7308★ 0cve_referencewww.exploit-db.com/exploits/41994/unverifiedcve_referencewww.exploit-db.com/exploits/44654/unverifiedexploitdbwww.exploit-db.com/exploits/44654unverifiedexploitdbwww.exploit-db.com/exploits/47168unverifiedexploitdbwww.exploit-db.com/exploits/41994unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://access.redhat.com/errata/RHSA-2017:1297https://access.redhat.com/errata/RHSA-2017:1298https://access.redhat.com/errata/RHSA-2017:1308https://access.redhat.com/errata/RHSA-2018:1854https://googleprojectzero.blogspot.com/2017/05/exploiting-linux-kernel-via-packet.htmlhttps://patchwork.ozlabs.org/patch/744811/https://patchwork.ozlabs.org/patch/744812/https://patchwork.ozlabs.org/patch/744813/https://source.android.com/security/bulletin/2017-07-01https://www.exploit-db.com/exploits/41994/https://www.exploit-db.com/exploits/44654/http://www.securityfocus.com/bid/97234