First published: Tue Feb 07 2017(Updated: )
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <4.9.10 | |
Debian Debian Linux | =8.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.3 | |
Redhat Enterprise Linux Server Aus | =7.4 | |
Redhat Enterprise Linux Server Eus | =7.3 | |
Redhat Enterprise Linux Server Eus | =7.4 | |
Redhat Enterprise Linux Server Eus | =7.5 | |
Redhat Enterprise Linux Workstation | =7.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.12.5-1 6.12.6-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2618 is a vulnerability in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files.
CVE-2017-2618 has a severity rating of medium.
An empty (null) write to /proc/pid/attr files can crash the system by causing the system to attempt to access unmapped kernel memory.
To fix CVE-2017-2618, update your Linux kernel to version 4.10 or higher.
You can find more information about CVE-2017-2618 in the following references: <ul><li><a href="https://git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/commit/?id=0c461cb727d146c9ef2d3e86214f498b78b7d125">Git commit</a></li><li><a href="https://marc.info/?l=selinux&m=148588165923772&w=2">SELinux mailing list</a></li><li><a href="https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1419916#c2">Red Hat Bugzilla</a></li></ul>