CVE-2017-16939: Use After Free
Last updated 29 November 2024
Other sources
Linux kernel built with the Transformation User configuration interface(CONFIGXFRMUSER) is vulnerable to a use-after-free issue. It could occur while closing a xfrm netlink socket, in xfrmdumppolicydone.
A user/process could use this flaw to potentially escalate their privileges on a system.
Upstream patch: --------------- -> https://git.kernel.org/linus/1137b5e2529a8f5ca8ee709288ecba3e68044df2
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/11/24/3 -> https://blogs.securiteam.com/index.php/archives/3535
— Red Hat
The XFRM dump policy implementation in net/xfrm/xfrmuser.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SORCVBUF setsockopt system call in conjunction with XFRMMSGGETPOLICY Netlink messages.
— Launchpad
Affected Software
Remediation
Patch Available
Mitigation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16939?
CVE-2017-16939 has a high severity due to its potential to allow privilege escalation in affected systems.
How do I fix CVE-2017-16939?
To fix CVE-2017-16939, upgrade to the patched versions of the Linux kernel, specifically versions 5.10.223-1 or later.
What systems are affected by CVE-2017-16939?
CVE-2017-16939 affects multiple versions of the Linux kernel, particularly those built with the CONFIG_XFRM_USER configuration.
Can CVE-2017-16939 be exploited remotely?
CVE-2017-16939 could potentially be exploited locally by a user with access to the vulnerable system.
What impact does CVE-2017-16939 have on system security?
CVE-2017-16939 could lead to unauthorized privilege escalation, compromising the integrity and security of the affected system.