UBUNTU-CVE-2017-12153
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-12153
UBUNTU-CVE-2017-12153
Summary:
Details: A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and system crash.
References: https://ubuntu.com/security/CVE-2017-12153, https://marc.info/?t=150525503100001&r=1&w=2, https://marc.info/?l=linux-wireless&m=150525493517953&w=2, https://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211.git/commit/?id=e785fa0a164aa11001cba931367c7f94ffaff888, https://ubuntu.com/security/notices/USN-3469-1, https://ubuntu.com/security/notices/USN-3469-2, https://ubuntu.com/security/notices/USN-3487-1, https://ubuntu.com/security/notices/USN-3583-1, https://ubuntu.com/security/notices/USN-3583-2, https://www.cve.org/CVERecord?id=CVE-2017-12153
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
