UBUNTU-CVE-2017-15115
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
02 / AFFECTED SOFTWARE
Affected packages
40 explicit affected versions
26 explicit affected versions
126 explicit affected versions
8 explicit affected versions
48 explicit affected versions
69 explicit affected versions
29 explicit affected versions
10 explicit affected versions
9 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
31 explicit affected versions
9 explicit affected versions
7 explicit affected versions
43 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
7 explicit affected versions
7 explicit affected versions
8 explicit affected versions
7 explicit affected versions
1 explicit affected versions
61 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
05 / REFERENCES
Further evidence
- http://seclists.org/oss-sec/2017/q4/282
- https://git.kernel.org/linus/df80cd9b28b9ebaa284a41df611dbf3a2d05ca74
- https://ubuntu.com/security/CVE-2017-15115
- https://ubuntu.com/security/notices/USN-3581-1
- https://ubuntu.com/security/notices/USN-3581-2
- https://ubuntu.com/security/notices/USN-3581-3
- https://ubuntu.com/security/notices/USN-3582-1
- https://ubuntu.com/security/notices/USN-3582-2
- https://ubuntu.com/security/notices/USN-3583-1
- https://ubuntu.com/security/notices/USN-3583-2
- https://www.cve.org/CVERecord?id=CVE-2017-15115