CVE-2017-1000405: Race Condition

Published Nov 22, 2017
·
Updated

A flaw was found in the patches used to fix the 'dirtycow' vulnerability CVE-2016-5195). The touchpmd() function can be accessed by getuserpages(). In this case, the pmd will become dirty without going through the Copy On Write cycle.

In the simplest example, a large page that is read-only can be modified, including page 0 of a processes virtual address space.

Upstream patch: https://github.com/torvalds/linux/commit/a8f97366452ed491d13cf1e44241bc0b5740b1f0

Vulnerability announcement: http://www.openwall.com/lists/oss-security/2017/11/30/1

Other sources

The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmdmkdirty() in the touchpmd() function inside the THP implementation. touchpmd() can be reached by getuserpages(). In such case, the pmd will become dirty. This scenario breaks the new canfollowwritepmd()'s logic - pmd can become dirty without going through a COW cycle. This bug is not as severe as the original "Dirty cow" because an ext4 file (or any other regular file) cannot be mapped using THP. Nevertheless, it does allow us to overwrite read-only huge pages. For example, the zero huge page and sealed shmem files can be overwritten (since their mapping can be populated using THP). Note that after the first write page-fault to the zero page, it will be replaced with a new fresh (and zeroed) thp.

Launchpad

Affected Software

10 affected componentsFixes available
Linux Linux kernel>=3.2.87<3.3
Linux Linux kernel>=3.10.106<3.11
Linux Linux kernel>=3.12.73<3.13
Linux Linux kernel>=3.16.42<3.16.52
Linux Linux kernel>=3.18.55<3.18.86
Linux Linux kernel>=4.1.41<4.1.48
Linux Linux kernel>=4.4.70<4.4.104
Linux Linux kernel>=4.9.7<4.9.67
Linux Linux kernel>=4.10<4.14.4
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1

Event History

Nov 22, 2017
Data Sourced
via Red Hat·07:34 PM
DescriptionSeverityAffected Software
Nov 30, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:23 PM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·01:33 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:40 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2017-1000405?

CVE-2017-1000405 has been classified as a moderate severity vulnerability due to its potential impact on Linux Kernel security.

2

How do I fix CVE-2017-1000405?

To fix CVE-2017-1000405, update your Linux Kernel to a version that includes the security patches addressing this vulnerability.

3

What types of systems are affected by CVE-2017-1000405?

CVE-2017-1000405 affects various versions of the Linux Kernel, specifically those between 3.2.87 and 4.14.4.

4

Is CVE-2017-1000405 related to CVE-2016-5195?

Yes, CVE-2017-1000405 is a flaw found in the patches that were implemented to fix the earlier CVE-2016-5195 'dirtycow' vulnerability.

5

What is the potential impact of CVE-2017-1000405?

The potential impact of CVE-2017-1000405 includes unauthorized access to system resources and possible data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203