CVE-2017-5970
The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.91% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=34b2cef20f19c87999fff3da4071e66937db9644Issue Tracking, Patch
- http://www.debian.org/security/2017/dsa-3791
- http://www.openwall.com/lists/oss-security/2017/02/12/3Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/96233
- https://access.redhat.com/errata/RHSA-2017:1842
- https://access.redhat.com/errata/RHSA-2017:2077
- https://access.redhat.com/errata/RHSA-2017:2669
- https://bugzilla.redhat.com/show_bug.cgi?id=1421638Issue Tracking, Patch
- https://github.com/torvalds/linux/commit/34b2cef20f19c87999fff3da4071e66937db9644Issue Tracking, Patch, Third Party Advisory
- https://patchwork.ozlabs.org/patch/724136/Patch, Third Party Advisory
- https://source.android.com/security/bulletin/2017-07-01
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=34b2cef20f19c87999fff3da4071e66937db9644Issue Tracking, Patch
- http://www.debian.org/security/2017/dsa-3791
- http://www.openwall.com/lists/oss-security/2017/02/12/3Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/96233
- https://access.redhat.com/errata/RHSA-2017:1842
- https://access.redhat.com/errata/RHSA-2017:2077
- https://access.redhat.com/errata/RHSA-2017:2669
- https://bugzilla.redhat.com/show_bug.cgi?id=1421638Issue Tracking, Patch
- https://github.com/torvalds/linux/commit/34b2cef20f19c87999fff3da4071e66937db9644Issue Tracking, Patch, Third Party Advisory
- https://patchwork.ozlabs.org/patch/724136/Patch, Third Party Advisory
- https://source.android.com/security/bulletin/2017-07-01
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.