The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

Patch is available.

Only vulnerable if unprivileged user namespaces are enabled.

CVSS v3 Base Score: 8.4 High

Files affected:

kernel-adaptation-sbj- lines 353-358 393-403 542-548 583-591

kernel-adaptation-sbj- lines 168-178 230-240 468-478 705-711 747-755


The question has been closed for the following reason "released in a software update" by lpr
released inämsänjoki

