First published: Tue Nov 02 2021(Updated: )
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
Credit: chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=4.13<4.13.7 | |
Netapp Cloud Backup | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H300e Firmware | ||
Netapp H300e | ||
Netapp H500e Firmware | ||
Netapp H500e | ||
Netapp H700e Firmware | ||
Netapp H700e | ||
Netapp H410s Firmware | ||
Netapp H410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-5123.
The severity of CVE-2017-5123 is high.
Linux kernel, Netapp Cloud Backup, Apple macOS Ventura, Apple macOS Big Sur, Apple macOS Monterey, Netapp H300e Firmware, Netapp H500e Firmware, Netapp H700e Firmware.
An attacker can exploit CVE-2017-5123 by using insufficient data validation in waitid to escape sandboxes on Linux.
Yes, there are references available for CVE-2017-5123. You can find them [here](https://crbug.com/772848), [here](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=96ca579a1ecc943b75beba58bebb0356f6cc4b51), and [here](https://security.netapp.com/advisory/ntap-20211223-0003/).