CVE-2017-6346

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Race condition in net/packet/af_packet.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKET_FANOUT setsockopt system calls.

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d199fab63c11998a602205f7ee7ff7c05c97164b

http://www.debian.org/security/2017/dsa-3804

http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.13

http://www.openwall.com/lists/oss-security/2017/02/28/6

http://www.securityfocus.com/bid/96508

https://github.com/torvalds/linux/commit/d199fab63c11998a602205f7ee7ff7c05c97164b

https://source.android.com/security/bulletin/2017-09-01

Details

Source: MITRE

Published: 2017-03-01

Updated: 2017-11-04

Type: CWE-362

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.9.12 (inclusive)

Tenable Plugins

View all (47 total)

IDNameProductFamilySeverity
124977EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1524)NessusHuawei Local Security Checks
high
111857Photon OS 1.0: Linux PHSA-2017-0008 (deprecated)NessusPhotonOS Local Security Checks
critical
108511SUSE SLES12 Security Update : kernel (SUSE-SU-2018:0664-1)NessusSuSE Local Security Checks
high
107106F5 Networks BIG-IP : Linux kernel vulnerability (K11023978)NessusF5 Networks Local Security Checks
high
107085SUSE SLES12 Security Update : kernel (SUSE-SU-2018:0562-1)NessusSuSE Local Security Checks
high
105284SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3315-1)NessusSuSE Local Security Checks
high
104965SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3160-1) (KRACK)NessusSuSE Local Security Checks
high
104964SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3158-1) (KRACK)NessusSuSE Local Security Checks
high
104963SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3157-1) (KRACK)NessusSuSE Local Security Checks
high
104961SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3154-1) (KRACK)NessusSuSE Local Security Checks
high
104960SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3153-1) (KRACK)NessusSuSE Local Security Checks
high
104959SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3152-1) (KRACK)NessusSuSE Local Security Checks
high
104958SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3151-1) (KRACK)NessusSuSE Local Security Checks
high
104957SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3150-1) (KRACK)NessusSuSE Local Security Checks
high
104956SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3149-1) (KRACK)NessusSuSE Local Security Checks
high
104955SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3148-1) (KRACK)NessusSuSE Local Security Checks
high
104954SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3147-1) (KRACK)NessusSuSE Local Security Checks
high
104953SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3146-1) (KRACK)NessusSuSE Local Security Checks
high
104952SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3145-1) (KRACK)NessusSuSE Local Security Checks
high
104880SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3132-1) (KRACK)NessusSuSE Local Security Checks
high
104879SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3131-1) (KRACK)NessusSuSE Local Security Checks
high
104878SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3130-1) (KRACK)NessusSuSE Local Security Checks
high
104877SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3127-1) (KRACK)NessusSuSE Local Security Checks
high
104876SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3125-1) (KRACK)NessusSuSE Local Security Checks
high
104875SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3124-1) (KRACK)NessusSuSE Local Security Checks
high
104874SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3123-1) (KRACK)NessusSuSE Local Security Checks
high
104873SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3119-1) (KRACK)NessusSuSE Local Security Checks
high
104872SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3118-1) (KRACK)NessusSuSE Local Security Checks
high
104871SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3117-1) (KRACK)NessusSuSE Local Security Checks
high
104805SUSE SLES12 Security Update : kernel (SUSE-SU-2017:3103-1) (KRACK)NessusSuSE Local Security Checks
high
104374SUSE SLES12 Security Update : kernel (SUSE-SU-2017:2920-1) (KRACK) (Stack Clash)NessusSuSE Local Security Checks
critical
104271SUSE SLES12 Security Update : kernel (SUSE-SU-2017:2908-1) (KRACK) (Stack Clash)NessusSuSE Local Security Checks
critical
104253SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:2869-1) (KRACK)NessusSuSE Local Security Checks
high
104246openSUSE Security Update : the Linux Kernel (openSUSE-2017-1224) (KRACK)NessusSuSE Local Security Checks
high
104171SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:2847-1) (KRACK)NessusSuSE Local Security Checks
high
104166openSUSE Security Update : the Linux Kernel (openSUSE-2017-1194) (KRACK)NessusSuSE Local Security Checks
high
103326Ubuntu 14.04 LTS : linux vulnerabilities (USN-3422-1) (BlueBorne)NessusUbuntu Local Security Checks
high
101929Ubuntu 16.04 LTS : linux-hwe vulnerabilities (USN-3361-1)NessusUbuntu Local Security Checks
critical
100320SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:1360-1)NessusSuSE Local Security Checks
critical
100150SUSE SLES12 Security Update : kernel (SUSE-SU-2017:1247-1)NessusSuSE Local Security Checks
critical
100023SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:1183-1)NessusSuSE Local Security Checks
high
99658Ubuntu 14.04 LTS : linux-lts-xenial vulnerabilities (USN-3265-2)NessusUbuntu Local Security Checks
critical
99657Ubuntu 16.04 LTS : linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities (USN-3265-1)NessusUbuntu Local Security Checks
critical
99157openSUSE Security Update : the Linux Kernel (openSUSE-2017-419)NessusSuSE Local Security Checks
high
99156openSUSE Security Update : the Linux Kernel (openSUSE-2017-418)NessusSuSE Local Security Checks
high
97640Debian DLA-849-1 : linux security updateNessusDebian Local Security Checks
high
97615Debian DSA-3804-1 : linux - security updateNessusDebian Local Security Checks
high