A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used to export socket's diagnostic information. As a result, up to 100 bytes of the slab data could be leaked to a userspace.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Base Score: 5.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | amazon-linux-upgrade-kernel | Oct 3, 2017 | Sep 20, 2017 |
| Centos_linux | — | centos-upgrade-kernelcentos-upgrade-kernel-rt | Oct 25, 2017 | Sep 20, 2017 |
| Debian | debian-upgrade-linux | Sep 25, 2017 | Sep 20, 2017 | |
| Oracle_linux | — | oracle-linux-upgrade-kernel | Oct 20, 2017 | Aug 23, 2017 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-kernelredhat-upgrade-kernel-rt | Oct 25, 2017 | Sep 20, 2017 | |
| Ubuntu | ubuntu-upgrade-linux-azureubuntu-upgrade-linux-gcpubuntu-upgrade-linux-hweubuntu-upgrade-linux-hwe-edge | Nov 19, 2024 | Jul 26, 2018 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jul 26, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub