CVE-2017-2618

MEDIUM
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.

References

http://www.securityfocus.com/bid/96272

https://access.redhat.com/errata/RHSA-2017:0931

https://access.redhat.com/errata/RHSA-2017:0932

https://access.redhat.com/errata/RHSA-2017:0933

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2618

https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=0c461cb727d146c9ef2d3e86214f498b78b7d125

https://marc.info/?l=selinux&m=148588165923772&w=2

https://www.debian.org/security/2017/dsa-3791

Details

Source: MITRE

Published: 2018-07-27

Updated: 2019-10-09

Type: CWE-682

Risk Information

CVSS v2

Base Score: 4.9

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
125301EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1508)NessusHuawei Local Security Checks
high
109158OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0035) (Dirty COW) (Meltdown) (Spectre)NessusOracleVM Local Security Checks
high
109156Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4071) (Dirty COW) (Meltdown) (Spectre)NessusOracle Linux Local Security Checks
high
105248OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0174) (BlueBorne) (Dirty COW) (Stack Clash)NessusOracleVM Local Security Checks
high
105247Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3659) (BlueBorne) (Dirty COW) (Stack Clash)NessusOracle Linux Local Security Checks
high
105146OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0172) (Dirty COW)NessusOracleVM Local Security Checks
high
105143Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3651) (Dirty COW)NessusOracle Linux Local Security Checks
high
104619OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0169)NessusOracleVM Local Security Checks
medium
104565Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3640)NessusOracle Linux Local Security Checks
medium
102511Oracle Linux 7 : kernel (ELSA-2017-1842-1) (Stack Clash)NessusOracle Linux Local Security Checks
critical
102261Ubuntu 14.04 LTS : linux vulnerabilities (USN-3381-1) (Stack Clash)NessusUbuntu Local Security Checks
high
101929Ubuntu 16.04 LTS : linux-hwe vulnerabilities (USN-3361-1)NessusUbuntu Local Security Checks
critical
101449Virtuozzo 7 : kernel / kernel-abi-whitelists / kernel-debug / etc (VZLSA-2017-0933)NessusVirtuozzo Local Security Checks
high
99938EulerOS 2.0 SP2 : kernel (EulerOS-SA-2017-1072)NessusHuawei Local Security Checks
high
99937EulerOS 2.0 SP1 : kernel (EulerOS-SA-2017-1071)NessusHuawei Local Security Checks
high
99386Oracle Linux 7 : kernel (ELSA-2017-0933-1)NessusOracle Linux Local Security Checks
high
99383CentOS 7 : kernel (CESA-2017:0933)NessusCentOS Local Security Checks
high
99351Scientific Linux Security Update : kernel on SL7.x x86_64 (20170412)NessusScientific Linux Local Security Checks
high
99346RHEL 7 : kernel (RHSA-2017:0933)NessusRed Hat Local Security Checks
high
99345RHEL 6 : MRG (RHSA-2017:0932)NessusRed Hat Local Security Checks
high
99344RHEL 7 : kernel-rt (RHSA-2017:0931)NessusRed Hat Local Security Checks
high
99333Oracle Linux 7 : kernel (ELSA-2017-0933)NessusOracle Linux Local Security Checks
high
97357Debian DSA-3791-1 : linux - security updateNessusDebian Local Security Checks
critical