Back to search
CVE-2017-7277
Published: Mar 28, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The TCP stack in the Linux kernel through 4.10.6 mishandles the SCM_TIMESTAMPING_OPT_STATS feature, which allows local users to obtain sensitive information from the kernel's internal socket data structures or cause a denial of service (out-of-bounds read) via crafted system calls, related to net/core/skbuff.c and net/socket.c.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://patchwork.ozlabs.org/patch/740636/
x_refsource_CONFIRM
https://lkml.org/lkml/2017/3/15/485
x_refsource_MISC
https://patchwork.ozlabs.org/patch/740639/
x_refsource_CONFIRM
97141
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now