Vulnerability CVE-2017-16995: Information

Description

The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: Dec. 27, 2017
Modified: Jan. 19, 2023
Error type identifier: CWE-119

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
DSA-4073
  • Third Party Advisory
https://github.com/torvalds/linux/commit/95a762e2c8c942780948091f8f2a4f32fce1ac6f
  • Third Party Advisory
https://bugs.chromium.org/p/project-zero/issues/detail?id=1454
  • Third Party Advisory
http://openwall.com/lists/oss-security/2017/12/21/2
  • Mailing List
  • Third Party Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=95a762e2c8c942780948091f8f2a4f32fce1ac6f
  • Vendor Advisory
102288
  • Third Party Advisory
  • VDB Entry
USN-3523-2
  • Third Party Advisory
44298
  • Third Party Advisory
  • VDB Entry
USN-3619-1
  • Third Party Advisory
USN-3619-2
  • Third Party Advisory
USN-3633-1
  • Third Party Advisory
45010
  • Third Party Advisory
  • VDB Entry
45058
  • Third Party Advisory
  • VDB Entry
https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=a6132276ab5dcc38b3299082efeb25b948263adb
  • Vendor Advisory
    1. Configuration 1

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      4.9
      End excliding
      4.9.72

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      4.10
      End excliding
      4.14.9

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*