First published: Thu Jul 20 2017(Updated: )
Kernel memory corruption due to a buffer overflow was found in brcmf_cfg80211_mgmt_tx() function in Linux kernels from v3.9-rc1 to v4.13-rc1. It can be triggered by sending crafted NL80211_CMD_FRAME packet via netlink. This flaw is unlikely to be triggered remotely, as certain userspace code is needed for this. An unprivileged local user could use this flaw to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely. References: <a href="http://seclists.org/oss-sec/2017/q3/208">http://seclists.org/oss-sec/2017/q3/208</a> <a href="https://bugzilla.novell.com/show_bug.cgi?id=1049645">https://bugzilla.novell.com/show_bug.cgi?id=1049645</a> <a href="https://www.spinics.net/lists/stable/msg180994.html">https://www.spinics.net/lists/stable/msg180994.html</a> Upstream patch: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8f44c9a41386729fea410e688959ddaa9d51be7c">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8f44c9a41386729fea410e688959ddaa9d51be7c</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=3.9<3.10.108 | |
Linux Linux kernel | >=3.11<3.16.48 | |
Linux Linux kernel | >=3.17<3.18.62 | |
Linux Linux kernel | >=3.19<4.1.43 | |
Linux Linux kernel | >=4.2<4.4.78 | |
Linux Linux kernel | >=4.5<4.9.39 | |
Linux Linux kernel | >=4.10<4.11.12 | |
Linux Linux kernel | >=4.12<4.12.3 | |
Google Android | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7541 is a vulnerability in the Linux kernel that allows local users to cause a denial of service or possibly gain privileges.
CVE-2017-7541 is considered to be a high severity vulnerability, with a severity value of 7.
CVE-2017-7541 can lead to a buffer overflow and system crash, as well as potential privilege escalation.
Versions before 4.12.3 are affected by CVE-2017-7541.
To mitigate CVE-2017-7541, it is recommended to update to Linux kernel version 4.12.3 or later.