Vulnerability Description
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.31, < 3.2.87 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.debian.org/security/2017/dsa-3804Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/03/07/6Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/96732Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037963Third Party AdvisoryVDB Entry
- https://a13xp0p0v.github.io/2017/03/24/CVE-2017-2636.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0931Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0932Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0933Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0986Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1125Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1126Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1232Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1233Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1488Third Party Advisory
FAQ
What is CVE-2017-2636?
CVE-2017-2636 is a vulnerability with a CVSS score of 7.0 (HIGH). Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
How severe is CVE-2017-2636?
CVE-2017-2636 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2636?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.