The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT table allocation when forking a new process, allowing a local attacker to achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program. This vulnerability only affected kernels built with CONFIG_MODIFY_LDT_SYSCALL=y.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 29, 2017 |
| Oracle_linux | — | Upgrade kernel-tools-libsUpgrade python-perfUpgrade kernel-develUpgrade kernel-debug-develUpgrade kernelUpgrade kernel-debugUpgrade kernel-tools-libs-develUpgrade kernel-abi-whitelistsUpgrade kernel-toolsUpgrade kernel-headersUpgrade perfUpgrade kernel-doc | Apr 19, 2018 | Nov 28, 2017 |
| Ubuntu | — | Upgrade linux-azureUpgrade linux-hweUpgrade linux-gcpUpgrade linux-hwe-edge | Nov 19, 2024 | Nov 29, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub