CVE-2017-14489: Input Validation
Last updated 29 November 2024
Other sources
The iscsiifrx function in drivers/scsi/scsitransportiscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.
— Launchpad
The iscsiifrx() function in 'drivers/scsi/scsitransportiscsi.c' in the Linux kernel since v2.6.24-rc1 through 4.13.2 allows local users to cause a denial of service (a system panic) by making a number of certain syscalls by leveraging incorrect length validation in the kernel code.
References:
http://seclists.org/oss-sec/2017/q3/506
A proposed upstream patch:
https://patchwork.kernel.org/patch/9923803/
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14489?
CVE-2017-14489 has been classified as a vulnerability that can cause a denial of service, specifically a system panic.
How do I fix CVE-2017-14489?
To fix CVE-2017-14489, upgrade your Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
Who is affected by CVE-2017-14489?
Local users of the Linux kernel versions through 4.13.2 are affected by CVE-2017-14489.
What type of vulnerability is CVE-2017-14489?
CVE-2017-14489 is a vulnerability related to incorrect length validation in the iscsi_if_rx function.
When was CVE-2017-14489 published?
CVE-2017-14489 was publicly disclosed on November 29, 2024.