SB2017101315 - Fedora 27 update for kernel
Published: October 13, 2017 Updated: April 24, 2025
Security Bulletin ID
SB2017101315
Severity
Low
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Null pointer dereference (CVE-ID: CVE-2017-15299)
The vulnerability allows a local attacker to cause DoS condition on the target system.The weakness exists due to the KEYS subsystem mishandles use of add_key for a key that already exists but is uninstantiated. A local attacker can supply specially crafted keys, trigger null pointer dereference and cause the service to crash.
Successful exploitation of the vulnerability results in denial of service.
2) Memory corruption (CVE-ID: CVE-2017-1000255)
The vulnerability allows a local user to execute arbitrary code with escalated privileges.The vulnerability exists due to a boundary error in the Linux kernel's when handling signal frame on PowerPC systems. A malicious local user process could craft a signal frame allowing an attacker to corrupt memory and execute arbitrary code on the target system with escalated privileges.
Remediation
Install update from vendor's website.