CVE-2017-9150: Infoleak
Last updated 29 November 2024
Other sources
The docheck function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allowptrleaks value available for restricting the output of the printbpfinsn function, which allows local users to obtain sensitive address information via crafted bpf system calls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernel (kernel/bpf verifier)to a version that resolves this vulnerability.Fixed in 4.11.1
Event History
Frequently Asked Questions
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2017-9150.
What is the severity level of CVE-2017-9150?
The severity level of CVE-2017-9150 is high.
Which software versions are affected by CVE-2017-9150?
Linux kernel versions before 4.11.1 are affected by this vulnerability.
How can I fix CVE-2017-9150?
To fix CVE-2017-9150, update your Linux kernel to version 4.11.1 or higher.
Where can I find more information about CVE-2017-9150?
You can find more information about CVE-2017-9150 on the following links: - [Linux Kernel Git Commit](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0d0e57697f162da4aa218b5feafe614fb666db07) - [Linux Kernel ChangeLog](http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.1) - [Project Zero Bug Report](https://bugs.chromium.org/p/project-zero/issues/detail?id=1251)