A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used to export socket's diagnostic information. As a result, up to 100 bytes of the slab data could be leaked to a userspace.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Base Score: 5.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade kernel | Oct 3, 2017 | Sep 20, 2017 |
| Centos_linux | — | Upgrade kernelUpgrade kernel-rt | Oct 25, 2017 | Sep 20, 2017 |
| Debian | — | Upgrade linux | Sep 25, 2017 | Sep 20, 2017 |
| Oracle_linux | — | Upgrade kernel | Oct 20, 2017 | Aug 23, 2017 |
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernelNo solution exists | Oct 25, 2017 | Sep 20, 2017 |
| Ubuntu | — | Upgrade linux-azureUpgrade linux-hweUpgrade linux-gcpUpgrade linux-hwe-edge | Nov 19, 2024 | Jul 26, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 26, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub