CVE Database
/

CVE-2017-15129

Back to search

CVE-2017-15129

Published: Jan 9, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

VendorProductVersions

n/a

Linux kernel v4.0-rc1 through v4.15-rc5

affected
Linux kernel v4.0-rc1 through v4.15-rc5

Weaknesses (CWE)

References

USN-3617-1
vendor-advisory
x_refsource_UBUNTU
USN-3619-2
vendor-advisory
x_refsource_UBUNTU
USN-3617-3
vendor-advisory
x_refsource_UBUNTU
USN-3632-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:1062
vendor-advisory
x_refsource_REDHAT
RHSA-2018:0654
vendor-advisory
x_refsource_REDHAT
102485
vdb-entry
x_refsource_BID
RHSA-2018:0676
vendor-advisory
x_refsource_REDHAT
USN-3617-2
vendor-advisory
x_refsource_UBUNTU
USN-3619-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:1946
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now