CVE-2017-5897: Critical severity Google Android vulnerability
An issue was found in the Linux kernel ipv6 implementation of GRE tunnels which allows a remote attacker to trigger an out-of-bounds access. At this time we understand no trust barrier has been crossed and there is no security implications in this flaw.
References:
http://seclists.org/oss-sec/2017/q1/323
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=7892032cfe67f4bde6fc2ee967e45a8fbaf33756
Other sources
The ip6greerr function in net/ipv6/ip6gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-5897.
What is the severity level of CVE-2017-5897?
CVE-2017-5897 has a severity level of high.
What is the impact of CVE-2017-5897?
CVE-2017-5897 allows remote attackers to trigger an out-of-bounds access, leading to unspecified impact.
Which software versions are affected by CVE-2017-5897?
Versions 4.10~ and up to 4.10~, 3.13.0-157.207, and 4.4.0-75.96 of the Linux kernel, as well as various other versions of Linux packages, are affected by CVE-2017-5897.
How can I fix CVE-2017-5897?
To fix CVE-2017-5897, update your Linux kernel to version 4.10~ or higher, or apply the appropriate security patches provided by your Linux distribution.