CVE

Id
104694  
CVE No.
CVE-2017-7874  
Status
Candidate  
Description
udevd in udev 232, when the Linux kernel 4.8.0 is used, does not properly verify the source of a Netlink message, which allows local users to execute arbitrary commands by leveraging access to the NETLINK_KOBJECT_UEVENT family, and the presence of the /lib/udev/rules.d/50-udev-default.rules file, to provide a crafted REMOVE_CMD value.  
Phase
Assigned (20170414)  
Votes
None (candidate not yet proposed)  
Comments