The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUF or (2) SO_RCVBUF option. CVSS v3 Base Score: 7.8high (attack range: local)

Patch available (kernel-3.5 and kernel-3.2 patch are the same, so no problem for kernel-3.4-sbj)...

File affected: kernel-adaptation-sbj- lines 577-598 ; 607-617 ; 629-636 ; 981-987 ; 1017-1023

