CVE-2017-0861

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.

References

http://lists.alioth.debian.org/pipermail/secure-testing-commits/2017-December/059967.html

http://www.securityfocus.com/bid/102329

https://access.redhat.com/errata/RHSA-2018:2390

https://access.redhat.com/errata/RHSA-2018:3083

https://access.redhat.com/errata/RHSA-2018:3096

https://access.redhat.com/errata/RHSA-2020:0036

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=362bca57f5d78220f8b5907b875961af9436e229

https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0

https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html

https://security-tracker.debian.org/tracker/CVE-2017-0861

https://source.android.com/security/bulletin/pixel/2017-11-01

https://usn.ubuntu.com/3583-1/

https://usn.ubuntu.com/3583-2/

https://usn.ubuntu.com/3617-1/

https://usn.ubuntu.com/3617-2/

https://usn.ubuntu.com/3617-3/

https://usn.ubuntu.com/3619-1/

https://usn.ubuntu.com/3619-2/

https://usn.ubuntu.com/3632-1/

https://www.debian.org/security/2018/dsa-4187

https://www.oracle.com/security-alerts/cpujul2020.html

https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html

Details

Source: MITRE

Published: 2017-11-16

Updated: 2020-07-15

Type: CWE-416

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Tenable Plugins

View all (76 total)

IDNameProductFamilySeverity
132700RHEL 7 : kernel (RHSA-2020:0036)NessusRed Hat Local Security Checks
critical
127425NewStart CGSL MAIN 4.05 : kernel Multiple Vulnerabilities (NS-SA-2019-0152)NessusNewStart CGSL Local Security Checks
high
127281NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2019-0074)NessusNewStart CGSL Local Security Checks
critical
127272NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0070)NessusNewStart CGSL Local Security Checks
critical
124992EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1539)NessusHuawei Local Security Checks
critical
121068Juniper Junos Space 18.4.x < 18.4R1 Multiple Vulnerabilities (JSA10917)NessusJunos Local Security Checks
high
119187Scientific Linux Security Update : kernel on SL7.x x86_64 (20181030)NessusScientific Linux Local Security Checks
high
118990CentOS 7 : kernel (CESA-2018:3083)NessusCentOS Local Security Checks
high
118770Oracle Linux 7 : kernel (ELSA-2018-3083)NessusOracle Linux Local Security Checks
high
118528RHEL 7 : kernel-rt (RHSA-2018:3096)NessusRed Hat Local Security Checks
high
118525RHEL 7 : kernel (RHSA-2018:3083)NessusRed Hat Local Security Checks
high
112018Virtuozzo 6 : cpupools / cpupools-features / etc (VZA-2018-055)NessusVirtuozzo Local Security Checks
high
111777Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20180814) (Foreshadow)NessusScientific Linux Local Security Checks
high
111731RHEL 6 : kernel (RHSA-2018:2390) (Foreshadow)NessusRed Hat Local Security Checks
high
111724Oracle Linux 6 : kernel (ELSA-2018-2390) (Foreshadow)NessusOracle Linux Local Security Checks
high
111704CentOS 6 : kernel (CESA-2018:2390) (Foreshadow)NessusCentOS Local Security Checks
high
109881Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2018-4110) (Meltdown) (Spectre)NessusOracle Linux Local Security Checks
high
109829Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4109) (Meltdown) (Spectre)NessusOracle Linux Local Security Checks
high
109797SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1273-1)NessusSuSE Local Security Checks
high
109796SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1272-1)NessusSuSE Local Security Checks
high
109795SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1269-1)NessusSuSE Local Security Checks
high
109794SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1268-1)NessusSuSE Local Security Checks
high
109793SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1267-1)NessusSuSE Local Security Checks
high
109792SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1266-1)NessusSuSE Local Security Checks
high
109791SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1264-1)NessusSuSE Local Security Checks
high
109790SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1262-1)NessusSuSE Local Security Checks
high
109789SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1261-1)NessusSuSE Local Security Checks
high
109788SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1259-1)NessusSuSE Local Security Checks
high
109786SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1257-1)NessusSuSE Local Security Checks
high
109785SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1256-1)NessusSuSE Local Security Checks
high
109784SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1255-1)NessusSuSE Local Security Checks
high
109783SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1254-1)NessusSuSE Local Security Checks
high
109782SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1253-1)NessusSuSE Local Security Checks
high
109781SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1251-1)NessusSuSE Local Security Checks
high
109780SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1250-1)NessusSuSE Local Security Checks
high
109779SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1247-1)NessusSuSE Local Security Checks
high
109778SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1245-1)NessusSuSE Local Security Checks
high
109777SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1244-1)NessusSuSE Local Security Checks
high
109776SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1243-1)NessusSuSE Local Security Checks
high
109775SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1242-1)NessusSuSE Local Security Checks
high
109774SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1241-1)NessusSuSE Local Security Checks
high
109772SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1237-1)NessusSuSE Local Security Checks
high
109771SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1236-1)NessusSuSE Local Security Checks
high
109770SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1235-1)NessusSuSE Local Security Checks
high
109769SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1234-1)NessusSuSE Local Security Checks
high
109768SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1233-1)NessusSuSE Local Security Checks
high
109767SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1232-1)NessusSuSE Local Security Checks
high
109766SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1231-1)NessusSuSE Local Security Checks
high
109765SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1230-1)NessusSuSE Local Security Checks
high
109764SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1229-1)NessusSuSE Local Security Checks
high
109763SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1227-1)NessusSuSE Local Security Checks
high
109762SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1226-1)NessusSuSE Local Security Checks
high
109761SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1224-1)NessusSuSE Local Security Checks
high
109759SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1222-1)NessusSuSE Local Security Checks
high
109758SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1221-1)NessusSuSE Local Security Checks
high
109757SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1220-1)NessusSuSE Local Security Checks
high
109668OracleVM 3.3 : Unbreakable / etc (OVMSA-2018-0041) (Spectre)NessusOracleVM Local Security Checks
high
109646SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1172-1)NessusSuSE Local Security Checks
high
109543Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4089) (Spectre)NessusOracle Linux Local Security Checks
high
109531Debian DLA-1369-1 : linux security update (Spectre)NessusDebian Local Security Checks
critical
109524Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2018-4088) (Spectre)NessusOracle Linux Local Security Checks
high
109517Debian DSA-4187-1 : linux - security update (Spectre)NessusDebian Local Security Checks
critical
109360SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1080-1) (Spectre)NessusSuSE Local Security Checks
high
109316Ubuntu 16.04 LTS : Linux kernel (Azure) vulnerabilities (USN-3632-1)NessusUbuntu Local Security Checks
high
109158OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0035) (Dirty COW) (Meltdown) (Spectre)NessusOracleVM Local Security Checks
high
109156Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4071) (Dirty COW) (Meltdown) (Spectre)NessusOracle Linux Local Security Checks
high
108878Ubuntu 14.04 LTS : linux-lts-xenial, linux-aws vulnerabilities (USN-3619-2)NessusUbuntu Local Security Checks
high
108842Ubuntu 16.04 LTS : linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities (USN-3619-1)NessusUbuntu Local Security Checks
high
108840Ubuntu 17.10 : linux-raspi2 vulnerabilities (USN-3617-3)NessusUbuntu Local Security Checks
high
108835Ubuntu 16.04 LTS : linux-hwe, linux-gcp, linux-oem vulnerabilities (USN-3617-2)NessusUbuntu Local Security Checks
high
108834Ubuntu 17.10 : linux vulnerabilities (USN-3617-1)NessusUbuntu Local Security Checks
high
107003Ubuntu 14.04 LTS : linux vulnerabilities (USN-3583-1) (Meltdown)NessusUbuntu Local Security Checks
critical
106706OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0017) (Meltdown)NessusOracleVM Local Security Checks
high
106670Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4025) (Meltdown)NessusOracle Linux Local Security Checks
high
106406EulerOS 2.0 SP1 : kernel (EulerOS-SA-2018-1031)NessusHuawei Local Security Checks
critical
105422Amazon Linux AMI : kernel (ALAS-2017-937) (Dirty COW)NessusAmazon Linux Local Security Checks
high