Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2017-1000405 | First vendor Publication | 2017-11-30 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 7 | ||
Base Score | 7 | Environmental Score | 7 |
impact SubScore | 5.9 | Temporal Score | 7 |
Exploitabality Sub Score | 1 | ||
Attack Vector | Local | Attack Complexity | High |
Privileges Required | Low | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 6.9 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can be reached by get_user_pages(). In such case, the pmd will become dirty. This scenario breaks the new can_follow_write_pmd()'s logic - pmd can become dirty without going through a COW cycle. This bug is not as severe as the original "Dirty cow" because an ext4 file (or any other regular file) cannot be mapped using THP. Nevertheless, it does allow us to overwrite read-only huge pages. For example, the zero huge page and sealed shmem files can be overwritten (since their mapping can be populated using THP). Note that after the first write page-fault to the zero page, it will be replaced with a new fresh (and zeroed) thp. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000405 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-362 | Race Condition |
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-08-17 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2017-2_0-0008.nasl - Type : ACT_GATHER_INFO |
2018-08-17 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2017-1_0-0093.nasl - Type : ACT_GATHER_INFO |
2018-04-18 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-956.nasl - Type : ACT_GATHER_INFO |
2018-02-22 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-956.nasl - Type : ACT_GATHER_INFO |
2018-01-16 | Name : The remote Virtuozzo host is missing a security update. File : Virtuozzo_VZA-2018-004.nasl - Type : ACT_GATHER_INFO |
2018-01-15 | Name : The remote Fedora host is missing a security update. File : fedora_2017-b0c1f44130.nasl - Type : ACT_GATHER_INFO |
2017-12-26 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2017-937.nasl - Type : ACT_GATHER_INFO |
2017-12-18 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3509-4.nasl - Type : ACT_GATHER_INFO |
2017-12-18 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3509-3.nasl - Type : ACT_GATHER_INFO |
2017-12-18 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-1390.nasl - Type : ACT_GATHER_INFO |
2017-12-14 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2017-0174.nasl - Type : ACT_GATHER_INFO |
2017-12-14 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2017-3659.nasl - Type : ACT_GATHER_INFO |
2017-12-12 | Name : The remote Virtuozzo host is missing a security update. File : Virtuozzo_VZA-2017-109.nasl - Type : ACT_GATHER_INFO |
2017-12-12 | Name : The remote Virtuozzo host is missing a security update. File : Virtuozzo_VZA-2017-111.nasl - Type : ACT_GATHER_INFO |
2017-12-12 | Name : The remote Virtuozzo host is missing a security update. File : Virtuozzo_VZA-2017-110.nasl - Type : ACT_GATHER_INFO |
2017-12-11 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-3249-1.nasl - Type : ACT_GATHER_INFO |
2017-12-11 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2017-0172.nasl - Type : ACT_GATHER_INFO |
2017-12-11 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2017-3651.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3511-1.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3510-1.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3509-2.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3509-1.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3508-2.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3508-1.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3507-2.nasl - Type : ACT_GATHER_INFO |
2017-12-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3507-1.nasl - Type : ACT_GATHER_INFO |
2017-12-07 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-3226-1.nasl - Type : ACT_GATHER_INFO |
2017-12-07 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-3225-1.nasl - Type : ACT_GATHER_INFO |
2017-12-05 | Name : The remote Fedora host is missing a security update. File : fedora_2017-9ea11e444d.nasl - Type : ACT_GATHER_INFO |
2017-12-05 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-3210-1.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 13:00:58 |
|
2024-10-25 01:43:37 |
|
2024-10-23 01:43:16 |
|
2024-08-02 12:44:25 |
|
2024-08-02 01:12:41 |
|
2024-03-12 12:39:40 |
|
2024-02-02 01:43:04 |
|
2024-02-01 12:12:08 |
|
2023-12-29 01:38:16 |
|
2023-11-22 01:37:56 |
|
2023-09-05 12:41:05 |
|
2023-09-05 01:11:52 |
|
2023-09-02 12:40:53 |
|
2023-09-02 01:12:09 |
|
2023-08-12 12:44:20 |
|
2023-08-12 01:11:38 |
|
2023-08-11 12:39:00 |
|
2023-08-11 01:11:58 |
|
2023-08-06 12:37:43 |
|
2023-08-06 01:11:38 |
|
2023-08-04 12:37:53 |
|
2023-08-04 01:11:41 |
|
2023-07-14 12:37:54 |
|
2023-07-14 01:11:41 |
|
2023-06-26 21:27:46 |
|
2023-06-06 12:33:13 |
|
2023-03-29 01:39:41 |
|
2023-03-28 12:11:58 |
|
2023-01-25 01:31:10 |
|
2022-10-11 12:33:50 |
|
2022-10-11 01:11:36 |
|
2022-09-09 01:30:01 |
|
2022-03-11 01:27:40 |
|
2022-02-01 01:26:35 |
|
2021-12-11 12:27:09 |
|
2021-12-11 01:25:26 |
|
2021-08-19 12:23:23 |
|
2021-05-25 12:22:18 |
|
2021-05-04 12:56:01 |
|
2021-04-22 02:07:56 |
|
2021-03-27 01:19:53 |
|
2020-12-12 12:17:29 |
|
2020-12-05 12:18:44 |
|
2020-09-25 01:16:51 |
|
2020-08-11 12:17:00 |
|
2020-08-08 01:16:56 |
|
2020-08-07 12:17:11 |
|
2020-08-07 01:17:50 |
|
2020-08-01 12:16:53 |
|
2020-07-30 01:17:34 |
|
2020-05-24 01:20:02 |
|
2020-05-23 02:02:14 |
|
2020-05-23 00:54:33 |
|
2019-09-12 12:08:41 |
|
2019-07-03 12:08:16 |
|
2019-06-15 12:08:36 |
|
2019-03-16 12:07:38 |
|
2018-12-18 12:07:16 |
|
2018-12-15 12:07:15 |
|
2018-11-20 12:07:29 |
|
2018-11-08 12:07:52 |
|
2018-10-30 12:09:48 |
|
2018-07-13 12:08:05 |
|
2018-04-25 12:08:04 |
|
2018-03-28 12:08:05 |
|
2018-02-13 13:21:47 |
|
2018-01-27 09:19:48 |
|
2017-12-24 09:21:56 |
|
2017-12-20 17:22:18 |
|
2017-12-19 13:23:50 |
|
2017-12-15 13:23:45 |
|
2017-12-13 13:23:52 |
|
2017-12-12 13:24:21 |
|
2017-12-09 13:24:14 |
|
2017-12-08 13:23:04 |
|
2017-12-06 13:23:08 |
|
2017-12-06 09:22:09 |
|
2017-12-03 09:21:44 |
|
2017-12-01 05:22:04 |
|