CVE-2017-7542
MEDIUMLinux kernel <= 4.12.3 - Denial of Service via Integer Overflow in ip6_find_1stfragopt
Title source: llmDescription
The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ability to open a raw socket.
References (12)
Core 12
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2017/dsa-3927
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0169
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/3583-2/
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2918
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2931
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99953
Various Sources x_refsource_confirm
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/3583-1/
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6399f1fae4ec29fab5ec76070435555e256ca3a6
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2017/dsa-3945
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/torvalds/linux/commit/6399f1fae4ec29fab5ec76070435555e256ca3a6
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2930
Scores
CVSS v3
5.5
EPSS
0.0046
EPSS Percentile
36.2%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-190
CWE-835
Status
published
Products (2)
linux/linux_kernel
< 4.12.3
n/a/Linux kernel versions up to and including 4.12
Linux kernel versions up to and including 4.12
Published
Jul 21, 2017
Tracked Since
Feb 18, 2026