Tracker / CVE-2017-9074
CVE-2017-9074
High 7.8
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.
Affected products and versions
| linux | linux_kernel · … → 3.2.89 |
|---|---|
| linux | linux_kernel · 3.17 → 3.18.56 |
| linux | linux_kernel · 3.19 → 4.1.42 |
| linux | linux_kernel · 3.3 → 3.16.44 |
| linux | linux_kernel · 4.10 → 4.11.4 |
| linux | linux_kernel · 4.2 → 4.4.71 |
| linux | linux_kernel · 4.5 → 4.9.31 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.