Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-7308 Details

Description

The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2017:1297 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:1298 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:1308 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:1854 CVEThird Party Advisory
https://googleprojectzero.blogspot.com/2017/05/exploiting-linux-kernel-via-packet.html CVEThird Party Advisory

see all 24 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-681Incorrect Conversion between Numeric Types[email protected]
CWE-787Out-of-bounds Write[email protected]

Affected Products

ProductVersions
linux linux kernel
>= 2.6.27, < 3.2.89
>= 3.3, < 3.10.107
>= 3.11, < 3.12.74
>= 3.13, < 3.16.44
>= 3.17, < 3.18.52

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

14 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-7308
NVD Published Date:
Mar 29, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-7308 Details - Not Deferred