CVE-2017-10662: High severity Google Android vulnerability
In was found that the sanitycheckrawsuper() function in 'fs/f2fs/super.c' file in the Linux kernel before 4.12-rc1 does not validate the f2fs filesystem segment count, which allows an unprivileged local user to cause a system panic and DoS. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://source.android.com/security/bulletin/2017-08-01#kernel-components
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b9dd46188edc2f0d1f37328637860bb65a771124
Other sources
The sanitycheckrawsuper function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment count, which allows local users to gain privileges via unspecified vectors.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-10662?
CVE-2017-10662 is a vulnerability in the Linux kernel that allows local users to gain privileges.
How severe is CVE-2017-10662?
CVE-2017-10662 has a severity rating of medium.
How does CVE-2017-10662 affect Linux?
CVE-2017-10662 affects the Linux kernel versions before 4.11.1.
How can the CVE-2017-10662 vulnerability be fixed?
To fix the CVE-2017-10662 vulnerability, update the Linux kernel to version 4.11.1 or higher.
Where can I find more information about CVE-2017-10662?
More information about CVE-2017-10662 can be found at the following links: [Git commit](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b9dd46188edc2f0d1f37328637860bb65a771124), [Linux kernel change log](http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.1), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1481146).