CVE-2017-7487: Use After Free
A reference counter leak in ipxitfioctl function was found which results into use after free vulnerability that's triggerable from unprivileged userspace when IPX interface is configured.
References:
http://seclists.org/oss-sec/2017/q2/251
https://patchwork.ozlabs.org/patch/757549/
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ee0d8d8482345ff97a75a7d747efc309f13b0d80
Other sources
The ipxitfioctl function in net/ipx/afipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernel (net/ipx/af_ipx.c ipxitf_ioctl)to a version that resolves this vulnerability.Patch ee0d8d8482345ff97a75a7d747efc309f13b0d80 - Upgrade
Upgrade
Linux kernel (net/ipx/af_ipx.c ipxitf_ioctl)to a version that resolves this vulnerability.Patch 757549
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID is CVE-2017-7487.
What is the severity level of CVE-2017-7487?
The severity level of CVE-2017-7487 is high.
How does CVE-2017-7487 affect Linux kernel?
CVE-2017-7487 allows local users to cause a denial of service (use-after-free) or possibly have other unspecified impact by exploiting mishandled reference counts in the ipxitf_ioctl function in net/ipx/af_ipx.c.
Which versions of Linux kernel are affected by CVE-2017-7487?
Linux kernel versions through 4.11.1 are affected by CVE-2017-7487.
Where can I find more information about CVE-2017-7487?
You can find more information about CVE-2017-7487 at the following references: http://www.securitytracker.com/id/1039237, http://www.securityfocus.com/bid/98439, http://www.debian.org/security/2017/dsa-3886.