CVE Database
/

CVE-2017-11176

Back to search

CVE-2017-11176

Published: Jul 11, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-3927
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:0169
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2918
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2931
vendor-advisory
x_refsource_REDHAT
99919
vdb-entry
x_refsource_BID
DSA-3945
vendor-advisory
x_refsource_DEBIAN
45553
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:3822
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2930
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now