Vulnerability CVE-2017-7895: Information

Description

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: April 28, 2017
Modified: Jan. 19, 2023
Error type identifier: CWE-119

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://github.com/torvalds/linux/commit/13bf9fbff0e5e099e2b6f003a0ab8ae145436309
  • Patch
  • Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=13bf9fbff0e5e099e2b6f003a0ab8ae145436309
  • Patch
  • Third Party Advisory
98085
  • Third Party Advisory
  • VDB Entry
DSA-3886
  • Third Party Advisory
RHSA-2017:2732
  • Third Party Advisory
RHSA-2017:2472
  • Third Party Advisory
RHSA-2017:2429
  • Third Party Advisory
RHSA-2017:2428
  • Third Party Advisory
RHSA-2017:2412
  • Third Party Advisory
RHSA-2017:1798
  • Third Party Advisory
RHSA-2017:1766
  • Third Party Advisory
RHSA-2017:1723
  • Third Party Advisory
RHSA-2017:1715
  • Third Party Advisory
RHSA-2017:1647
  • Third Party Advisory
RHSA-2017:1616
  • Third Party Advisory
RHSA-2017:1615
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      End excliding
      3.2.89

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      3.3
      End excliding
      3.16.44

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      3.17.0
      End excliding
      4.1.40

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      4.2
      End excliding
      4.4.67

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      4.5.0
      End excliding
      4.9.26

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      4.10
      End excliding
      4.10.14

      Configuration 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*