imPC@ndo IT

Tracker / CVE-2017-7482

CVE-2017-7482

High 7.8

In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.

Affected products and versions

debian debian_linux
linux linux_kernel · … → 3.2.90
linux linux_kernel · 3.11 → 3.16.45
linux linux_kernel · 3.17 → 3.18.59
linux linux_kernel · 3.19 → 4.1.43
linux linux_kernel · 3.3 → 3.10.108
linux linux_kernel · 4.10 → 4.11.8
linux linux_kernel · 4.2 → 4.4.75
linux linux_kernel · 4.5 → 4.9.35
redhat enterprise_mrg

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References