CVE-2017-17448 log
Source |
|
Severity | High |
Remote | No |
Type | Access restriction bypass |
Description | It has been discovered that net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions because the nfnl_cthelper_list data structure is shared across all net namespaces. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-993 | linux-lts | 4.9.78-1 | 4.9.79-1 | High | Fixed | |
AVG-574 | linux-hardened | 4.14.7.a-1 | 4.14.11.a-1 | High | Fixed | FS#56832 |
AVG-572 | linux-zen | 4.14.11-1 | 4.16.1-1 | High | Fixed | |
AVG-567 | linux | 4.14.11-1 | 4.16-1 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
05 Jan 2018 | ASA-201801-4 | AVG-574 | linux-hardened | High | multiple issues |
References |
---|
https://git.kernel.org/linus/4b380c42f7d00a395feede754f0bc2292eebe6e5 |
Notes |
---|
4.15 |