← Zuruck zu CVEs
CVE-2017-7558
N/ABeschreibung
A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used to export socket's diagnostic information. As a result, up to 100 bytes of the slab data could be leaked to a userspace.
CVE Details
CVSS v3.1 BewertungN/A
Veroffentlicht7/26/2018
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
debian:debian_linuxlinux:linux_kernel
Schwachen (CWE)
CWE-125CWE-125
Referenzen
http://seclists.org/oss-sec/2017/q3/338(secalert@redhat.com)
http://www.securityfocus.com/bid/100466(secalert@redhat.com)
http://www.securitytracker.com/id/1039221(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:2918(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:2930(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:2931(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7558(secalert@redhat.com)
https://marc.info/?l=linux-netdev&m=150348777122761&w=2(secalert@redhat.com)
https://www.debian.org/security/2017/dsa-3981(secalert@redhat.com)
http://seclists.org/oss-sec/2017/q3/338(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/100466(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1039221(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:2918(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:2930(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:2931(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7558(af854a3a-2127-422b-91ae-364da2661108)
https://marc.info/?l=linux-netdev&m=150348777122761&w=2(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2017/dsa-3981(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.