Back to search
CVE-2017-18017
Published: Jan 3, 2018
Modified: Jan 3, 2025
PUBLISHED
Description
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-4187
vendor-advisory
x_refsource_DEBIAN
USN-3583-2
vendor-advisory
x_refsource_UBUNTU
http://patchwork.ozlabs.org/patch/746618/
x_refsource_MISC
RHSA-2018:1737
vendor-advisory
x_refsource_REDHAT
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.36
x_refsource_MISC
https://lkml.org/lkml/2017/4/2/13
x_refsource_MISC
RHSA-2018:1062
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1319
vendor-advisory
x_refsource_REDHAT
USN-3583-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:0676
vendor-advisory
x_refsource_REDHAT
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1739765
x_refsource_MISC
RHSA-2018:1170
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1130
vendor-advisory
x_refsource_REDHAT
[debian-lts-announce] 20180502 [SECURITY] [DLA 1369-1] linux security update
mailing-list
x_refsource_MLIST
102367
vdb-entry
x_refsource_BID
SUSE-SU-2018:0834
vendor-advisory
x_refsource_SUSE
SUSE-SU-2018:0848
vendor-advisory
x_refsource_SUSE
SUSE-SU-2018:0383
vendor-advisory
x_refsource_SUSE
USN-3583-1
vendor-advisory
x_refsource_UBUNTU
https://support.f5.com/csp/article/K18352029
x_refsource_CONFIRM
SUSE-SU-2018:0555
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2018:0408
vendor-advisory
x_refsource_SUSE
SUSE-SU-2018:0986
vendor-advisory
x_refsource_SUSE
SUSE-SU-2018:0416
vendor-advisory
x_refsource_SUSE
SUSE-SU-2018:0482
vendor-advisory
x_refsource_SUSE
SUSE-SU-2018:0841
vendor-advisory
x_refsource_SUSE
USN-3583-2
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2018:0660
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now