Linux Kernel 'fs/userfaultfd. c' reuse memory corruption vulnerability after local release (CVE-2017-15126)
Linux Kernel 'fs/userfaultfd. c' reuse memory corruption vulnerability after local release (CVE-2017-15126)
Release date:
Updated on:
Affected Systems:
Linux kernel < 4.13.6
Description:
Bugtraq id: 102516
CVE (CAN) ID: CVE-2017-15126
Linux Kernel is the Kernel of the Linux operating system.
In Linux kernel <4.13.6, fs/userfaultfd. c has the re-exploitation vulnerability after release. After successful exploitation, local attackers can execute arbitrary code in the kernel context.
<* Source: Mark Rutland
*>
Suggestion:
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.6
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1523481
Https://access.redhat.com/security/cve/CVE-2017-15126
Http://www.linux.org/
Https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit? Id = 384632e67e0829deb8015ee6ad916b180049d252
Https://github.com/torvalds/linux/commit/384632e67e0829deb8015ee6ad916b180049d252