CVE-2017-17712: Race Condition
A flaw was found in the kernels implementation of rawsendmsg allowing a local attacker to panic the kernel or possible leak kernel addresses. A local attacker with the privilege of creating raw sockets, can abuse a possible race condition when setting the socket option to allow the kernel to automatically create ip header values.
References:
http://seclists.org/oss-sec/2017/q4/401
https://patchwork.ozlabs.org/patch/846641/
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8f659a03a0ba9289b9aeb9b4470e6fb263d6f483
Other sources
The rawsendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows a local user to execute code and gain privileges.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
linux kernel net/ipv4/raw.c raw_sendmsg (inet->hdrincl race)to a version that resolves this vulnerability.Patch 8f659a03a0ba9289b9aeb9b4470e6fb263d6f483