Vulnerability Description
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 3.2.92 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Aus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions | 7.4 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e38daIssue TrackingPatchThird Party Advisory
- http://www.debian.org/security/2017/dsa-3981Mailing ListThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.15Release NotesVendor Advisory
- http://www.securityfocus.com/bid/100215Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3083Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3096Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4057Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4058Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0036Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1481136Issue Tracking
- https://github.com/torvalds/linux/commit/1e38da300e1e395a15048b0af1e5305bd91402fIssue TrackingPatchThird Party Advisory
- https://source.android.com/security/bulletin/2017-08-01PatchVendor Advisory
- https://www.exploit-db.com/exploits/43345/Third Party AdvisoryVDB Entry
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e38daIssue TrackingPatchThird Party Advisory
- http://www.debian.org/security/2017/dsa-3981Mailing ListThird Party Advisory
FAQ
What is CVE-2017-10661?
CVE-2017-10661 is a vulnerability with a CVSS score of 7.0 (HIGH). Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descripto...
How severe is CVE-2017-10661?
CVE-2017-10661 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-10661?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux, Redhat Enterprise Linux Aus, Redhat Enterprise Linux Server Eus, Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions.