NVD

Id
85002  
Name
CVE-2017-7979  
Description
The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized memory access and refcount underflow, and system hang or crash) or possibly have unspecified other impact via tc filter add commands in certain contexts. NOTE: this does not affect stable kernels, such as 4.10.x, from kernel.org.  
Reject
 
CVSS Version
2  
CVSS Score
7.2  
Severity
High  
CVSS Base Score
7.2  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
3.9  
CVSS Vector
(AV:L/AC:L/Au:N/C:C/I:C/A:C)  
Pub Date
2017-04-27  
Published
2017-04-19  
Modified Date
2017-04-25  
Seq
2017-7979  

Actions