UBUNTU-CVE-2017-2671
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.
02 / AFFECTED SOFTWARE
Affected packages
136 explicit affected versions
30 explicit affected versions
52 explicit affected versions
10 explicit affected versions
8 explicit affected versions
17 explicit affected versions
28 explicit affected versions
25 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.
05 / REFERENCES
Further evidence
- http://openwall.com/lists/oss-security/2017/04/04/8
- http://www.openwall.com/lists/oss-security/2017/03/24/6
- https://github.com/danieljiang0415/android_kernel_crash_poc
- https://twitter.com/danieljiang0415/status/845116665184497664
- https://ubuntu.com/security/CVE-2017-2671
- https://ubuntu.com/security/notices/USN-3312-1
- https://ubuntu.com/security/notices/USN-3312-2
- https://ubuntu.com/security/notices/USN-3314-1
- https://ubuntu.com/security/notices/USN-3361-1
- https://ubuntu.com/security/notices/USN-3754-1
- https://www.cve.org/CVERecord?id=CVE-2017-2671