CVE-2017-9242: Input Validation
Published May 27, 2017
·Updated
Last updated 29 November 2024
Other sources
The ip6appenddata function in net/ipv6/ip6output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.
— Launchpad
Affected Software
2 affected componentsFixes available
Linux Linux kernel<=4.11.3
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
Remediation
Event History
May 27, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 29, 2017
Data Sourced
via Red Hat·09:59 AM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:42 PM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·02:05 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-9242?
The severity of CVE-2017-9242 is medium.
2
How does CVE-2017-9242 affect Linux kernel?
CVE-2017-9242 allows local users to cause a denial of service (system crash) via crafted system calls.
3
Which versions of the Linux kernel are affected by CVE-2017-9242?
The Linux kernel through 4.11.3 is affected by CVE-2017-9242.
4
How can I fix CVE-2017-9242?
Apply the remedy provided by the Ubuntu source for the affected package versions.
5
Where can I find more information about CVE-2017-9242?
More information about CVE-2017-9242 can be found at the provided reference links.