Back to search
CVE-2017-11176
Published: Jul 11, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-3927
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:0169
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2918
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2931
vendor-advisory
x_refsource_REDHAT
99919
vdb-entry
x_refsource_BID
DSA-3945
vendor-advisory
x_refsource_DEBIAN
45553
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:3822
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2930
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now