Bug 1070266 - (CVE-2017-17052) VUL-0: CVE-2017-17052: kernel-source: The mm_init function in kernel/fork.c in the Linux kernel before4.12.10 does not clear the ->exe_file member of a new process'smm_struct, allowing a local attacker to achieve a use-after-free orpossi
(CVE-2017-17052)
VUL-0: CVE-2017-17052: kernel-source: The mm_init function in kernel/fork.c i...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/195760/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-11-29 07:14 UTC by Marcus Meissner
Modified: 2022-03-04 20:18 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-11-29 07:14:23 UTC
CVE-2017-17052

The mm_init function in kernel/fork.c in the Linux kernel before
4.12.10 does not clear the ->exe_file member of a new process's
mm_struct, allowing a local attacker to achieve a use-after-free or
possibly have unspecified other impact by running a specially crafted
program.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-17052
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17052

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2b7e8665b4ff51c034c55df3cff76518d1a9ee3a
Comment 1 Marcus Meissner 2017-11-29 07:15:02 UTC
Fixes: 7c051267931a

points to 4.7+
Comment 3 Michal Hocko 2017-11-29 12:25:39 UTC
We already have the patch in SLE15 via stable. I've update the references. Older kernels shouldn't be affected.
Comment 7 Michal Hocko 2017-11-29 13:24:04 UTC
OK, understood and thanks for the clarification. I expect this is done from my side then. Bouncing back to sec team.
Comment 8 Marcus Meissner 2017-11-30 16:17:39 UTC
fixed in relevant branches