HIGH · 7.0

CVE-2017-10661

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descripto...

Vulnerability Description

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

CVSS Score

7.0

HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel< 3.2.92
RedhatEnterprise Linux7.0
RedhatEnterprise Linux Aus7.4
RedhatEnterprise Linux Server Eus7.5
RedhatEnterprise Linux Server For Power Little Endian Update Services For Sap Solutions7.4
DebianDebian Linux8.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-10661?

CVE-2017-10661 is a vulnerability with a CVSS score of 7.0 (HIGH). Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descripto...

How severe is CVE-2017-10661?

CVE-2017-10661 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-10661?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux, Redhat Enterprise Linux Aus, Redhat Enterprise Linux Server Eus, Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions.