CVE-2017-8824

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.

References

http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html

http://lists.openwall.net/netdev/2017/12/04/224

http://www.openwall.com/lists/oss-security/2017/12/05/1

http://www.securityfocus.com/bid/102056

https://access.redhat.com/errata/RHSA-2018:0399

https://access.redhat.com/errata/RHSA-2018:0676

https://access.redhat.com/errata/RHSA-2018:1062

https://access.redhat.com/errata/RHSA-2018:1130

https://access.redhat.com/errata/RHSA-2018:1170

https://access.redhat.com/errata/RHSA-2018:1216

https://access.redhat.com/errata/RHSA-2018:1319

https://access.redhat.com/errata/RHSA-2018:3822

https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0

https://lists.debian.org/debian-lts-announce/2017/12/msg00004.html

https://usn.ubuntu.com/3581-1/

https://usn.ubuntu.com/3581-2/

https://usn.ubuntu.com/3581-3/

https://usn.ubuntu.com/3582-1/

https://usn.ubuntu.com/3582-2/

https://usn.ubuntu.com/3583-1/

https://usn.ubuntu.com/3583-2/

https://www.debian.org/security/2017/dsa-4073

https://www.debian.org/security/2018/dsa-4082

https://www.exploit-db.com/exploits/43234/

Details

Source: MITRE

Published: 2017-12-05

Updated: 2018-12-13

Type: CWE-416

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.14.3 (inclusive)

Tenable Plugins

View all (64 total)

IDNameProductFamilySeverity
127408NewStart CGSL MAIN 4.05 : kernel Multiple Vulnerabilities (NS-SA-2019-0143)NessusNewStart CGSL Local Security Checks
critical
127233NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2019-0049)NessusNewStart CGSL Local Security Checks
high
127222NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0044)NessusNewStart CGSL Local Security Checks
high
124827EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1504)NessusHuawei Local Security Checks
critical
124800EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1476)NessusHuawei Local Security Checks
high
121903Photon OS 2.0: Linux PHSA-2018-2.0-0009NessusPhotonOS Local Security Checks
critical
121794Photon OS 1.0: Linux PHSA-2018-1.0-0096NessusPhotonOS Local Security Checks
critical
118633F5 Networks BIG-IP : Linux kernel vulnerability (K15526101)NessusF5 Networks Local Security Checks
high
111907Photon OS 1.0: Linux / Rsync PHSA-2018-1.0-0096 (deprecated)NessusPhotonOS Local Security Checks
critical
111278Photon OS 2.0 : glibc / linux / rsync / curl (PhotonOS-PHSA-2018-2.0-0009) (deprecated)NessusPhotonOS Local Security Checks
critical
111144Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2018-4172)NessusOracle Linux Local Security Checks
high
111022OracleVM 3.3 : Unbreakable / etc (OVMSA-2018-0237)NessusOracleVM Local Security Checks
high
111021OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0236)NessusOracleVM Local Security Checks
critical
110998Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4164)NessusOracle Linux Local Security Checks
high
110997Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4161)NessusOracle Linux Local Security Checks
critical
109881Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2018-4110)NessusOracle Linux Local Security Checks
high
109829Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4109)NessusOracle Linux Local Security Checks
high
109668OracleVM 3.3 : Unbreakable / etc (OVMSA-2018-0041) (Spectre)NessusOracleVM Local Security Checks
high
109655CentOS 6 : kernel (CESA-2018:1319) (Meltdown)NessusCentOS Local Security Checks
critical
109643Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20180508) (Meltdown)NessusScientific Linux Local Security Checks
critical
109634RHEL 6 : kernel (RHSA-2018:1319) (Meltdown)NessusRed Hat Local Security Checks
critical
109629Oracle Linux 6 : kernel (ELSA-2018-1319)NessusOracle Linux Local Security Checks
critical
109449Scientific Linux Security Update : kernel on SL7.x x86_64 (20180410) (Meltdown)NessusScientific Linux Local Security Checks
critical
109380CentOS 7 : kernel (CESA-2018:1062)NessusCentOS Local Security Checks
critical
109336RHEL 7 : kernel (RHSA-2018:1216)NessusRed Hat Local Security Checks
high
109335RHEL 6 : MRG (RHSA-2018:1170)NessusRed Hat Local Security Checks
critical
109158OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0035) (Dirty COW) (Meltdown) (Spectre)NessusOracleVM Local Security Checks
high
109156Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4071)NessusOracle Linux Local Security Checks
high
109116RHEL 7 : kernel (RHSA-2018:1130)NessusRed Hat Local Security Checks
critical
109113Oracle Linux 7 : kernel (ELSA-2018-1062)NessusOracle Linux Local Security Checks
critical
108997RHEL 7 : kernel (RHSA-2018:1062)NessusRed Hat Local Security Checks
critical
108984RHEL 7 : kernel-rt (RHSA-2018:0676)NessusRed Hat Local Security Checks
critical
107187RHEL 7 : kernel (RHSA-2018:0399)NessusRed Hat Local Security Checks
high
107052Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2018-4041)NessusOracle Linux Local Security Checks
high
107051Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4040)NessusOracle Linux Local Security Checks
high
107003Ubuntu 14.04 LTS : linux vulnerabilities (USN-3583-1) (Meltdown)NessusUbuntu Local Security Checks
critical
106973Ubuntu 14.04 LTS : linux-lts-xenial, linux-aws vulnerabilities (USN-3582-2) (Spectre)NessusUbuntu Local Security Checks
high
106972Ubuntu 16.04 LTS : linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities (USN-3582-1) (Spectre)NessusUbuntu Local Security Checks
high
106971Ubuntu 17.10 : linux-raspi2 vulnerabilities (USN-3581-3)NessusUbuntu Local Security Checks
high
106970Ubuntu 16.04 LTS : linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities (USN-3581-2) (Spectre)NessusUbuntu Local Security Checks
high
106969Ubuntu 17.10 : linux vulnerabilities (USN-3581-1) (Spectre)NessusUbuntu Local Security Checks
high
106706OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0017) (Meltdown)NessusOracleVM Local Security Checks
high
106670Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4025)NessusOracle Linux Local Security Checks
high
106406EulerOS 2.0 SP1 : kernel (EulerOS-SA-2018-1031)NessusHuawei Local Security Checks
critical
106171Amazon Linux AMI : kernel (ALAS-2018-944)NessusAmazon Linux Local Security Checks
high
106167EulerOS 2.0 SP2 : kernel (EulerOS-SA-2018-1026)NessusHuawei Local Security Checks
high
106095SUSE SLES12 Security Update : kernel (SUSE-SU-2018:0115-1) (Meltdown) (Spectre)NessusSuSE Local Security Checks
high
106052Virtuozzo 7 : readykernel-patch (VZA-2018-004)NessusVirtuozzo Local Security Checks
critical
105819Fedora 27 : kernel (2017-129969aa8a)NessusFedora Local Security Checks
high
105704Debian DSA-4082-1 : linux - security update (Meltdown)NessusDebian Local Security Checks
high
105685SUSE SLES11 Security Update : kernel (SUSE-SU-2018:0040-1) (BlueBorne) (KRACK) (Meltdown) (Spectre)NessusSuSE Local Security Checks
high
105647SUSE SLES12 Security Update : kernel (SUSE-SU-2018:0031-1) (Meltdown) (Spectre)NessusSuSE Local Security Checks
high
105575SUSE SLES11 Security Update : kernel (SUSE-SU-2018:0011-1) (Meltdown) (Spectre)NessusSuSE Local Security Checks
high
105461SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:3410-1)NessusSuSE Local Security Checks
high
105460SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:3398-1)NessusSuSE Local Security Checks
high
105433Debian DSA-4073-1 : linux - security updateNessusDebian Local Security Checks
high
105383Fedora 26 : kernel (2017-ba6b6e71f7)NessusFedora Local Security Checks
high
105364openSUSE Security Update : the Linux Kernel (openSUSE-2017-1391) (Dirty COW)NessusSuSE Local Security Checks
high
105344openSUSE Security Update : the Linux Kernel (openSUSE-2017-1390) (Dirty COW)NessusSuSE Local Security Checks
high
105324Virtuozzo 6 : parallels-server-bm-release / vzkernel / etc (VZA-2017-114)NessusVirtuozzo Local Security Checks
high
105167Virtuozzo 7 : readykernel-patch (VZA-2017-111)NessusVirtuozzo Local Security Checks
high
105166Virtuozzo 7 : readykernel-patch (VZA-2017-110)NessusVirtuozzo Local Security Checks
high
105165Virtuozzo 7 : readykernel-patch (VZA-2017-109)NessusVirtuozzo Local Security Checks
high
105116Debian DLA-1200-1 : linux security update (KRACK)NessusDebian Local Security Checks
high