CVE-2017-7979

7.8 HIGH
Published: April 19, 2017 Modified: May 13, 2026
View on NVD

Description

The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized memory access and refcount underflow, and system hang or crash) or possibly have unspecified other impact via "tc filter add" commands in certain contexts. NOTE: this does not affect stable kernels, such as 4.10.x, from kernel.org.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://marc.info/?l=linux-netdev&m=149200742616349
Source: cve@mitre.org
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149200746116365
Source: cve@mitre.org
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149200746116366
Source: cve@mitre.org
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149251041420194
Source: cve@mitre.org
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149251041420195
Source: cve@mitre.org
Mailing List Patch Third Party Advisory
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1682368
Source: cve@mitre.org
Issue Tracking Patch
https://bugzilla.proxmox.com/show_bug.cgi?id=1351
Source: cve@mitre.org
Issue Tracking Patch
http://marc.info/?l=linux-netdev&m=149200742616349
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149200746116365
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149200746116366
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149251041420194
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Patch Third Party Advisory
http://marc.info/?l=linux-netdev&m=149251041420195
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Patch Third Party Advisory
http://www.securityfocus.com/bid/97969
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1682368
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Patch
https://bugzilla.proxmox.com/show_bug.cgi?id=1351
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Patch

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.8 / 10.0
EPSS (Exploit Probability)
0.4%
31th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

linux