CVE-2017-17448 log
| Source |
|
| Severity | High |
| Remote | No |
| Type | Access restriction bypass |
| Description | It has been discovered that net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions because the nfnl_cthelper_list data structure is shared across all net namespaces. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-993 | linux-lts | 4.9.78-1 | 4.9.79-1 | High | Fixed | |
| AVG-574 | linux-hardened | 4.14.7.a-1 | 4.14.11.a-1 | High | Fixed | FS#56832 |
| AVG-572 | linux-zen | 4.14.11-1 | 4.16.1-1 | High | Fixed | |
| AVG-567 | linux | 4.14.11-1 | 4.16-1 | High | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 05 Jan 2018 | ASA-201801-4 | AVG-574 | linux-hardened | High | multiple issues |
| References |
|---|
https://git.kernel.org/linus/4b380c42f7d00a395feede754f0bc2292eebe6e5 |
| Notes |
|---|
4.15 |