MEDIUM · 4.7

CVE-2017-15129

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::c...

Vulnerability Description

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 4.0, < 4.14.11
FedoraprojectFedora27
CanonicalUbuntu Linux14.04
RedhatEnterprise Linux7.0
RedhatEnterprise Linux Compute Node Eus7.4
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux Eus7.4
RedhatEnterprise Linux For Ibm Z Systems7.0
RedhatEnterprise Linux For Ibm Z Systems Eus7.4
RedhatEnterprise Linux For Power Big Endian7.0
RedhatEnterprise Linux For Power Big Endian Eus7.4
RedhatEnterprise Linux For Power Little Endian Eus7.4
RedhatEnterprise Linux For Real Time7.0
RedhatEnterprise Linux For Real Time For Nfv7
RedhatEnterprise Linux For Scientific Computing7.0
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Server Aus7.4
RedhatEnterprise Linux Server Tus7.4
RedhatEnterprise Linux Server Update Services For Sap Solutions7.4
RedhatEnterprise Linux Workstation7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-15129?

CVE-2017-15129 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::c...

How severe is CVE-2017-15129?

CVE-2017-15129 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-15129?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Canonical Ubuntu Linux, Redhat Enterprise Linux, Redhat Enterprise Linux Compute Node Eus.