CVE
- Id
- 104694
- CVE No.
- CVE-2017-7874
- Status
- Candidate
- Description
- udevd in udev 232, when the Linux kernel 4.8.0 is used, does not properly verify the source of a Netlink message, which allows local users to execute arbitrary commands by leveraging access to the NETLINK_KOBJECT_UEVENT family, and the presence of the /lib/udev/rules.d/50-udev-default.rules file, to provide a crafted REMOVE_CMD value.
- Phase
- Assigned (20170414)
- Votes
- None (candidate not yet proposed)
- Comments