check for the required netlink attributes presence in kernel-net-wireless-nl80211 CVE-2017-12153 remote

asked 2017-10-19 01:20:47 +0300

this post is marked as community wiki

This post is a wiki. Anyone with karma >75 is welcome to improve it.

updated 2017-10-19 01:20:47 +0300

lpr gravatar image

A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and system crash.

medium (attack range: remote)

Upstream-Patch is available and equal to 3.2-backport.

File affected: kernel-adaptation-sbj-3.4.108.20161101.1/net/wireless/nl80211.c lines 6218-6223

edit retag flag offensive close delete