CVE-2017-7895

Impact:
Important
Public Date:
2017-04-28
CWE:
CWE-125
Bugzilla:
1446103: CVE-2017-7895 kernel: NFSv3 server does not properly handle payload bounds checking of WRITE requests
The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lacked certain checks for the end of a buffer. A remote attacker could trigger a pointer-arithmetic error or possibly cause other unspecified impacts using crafted requests related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

Find out more about CVE-2017-7895 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 may address this issue.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact None
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux Server TUS (v. 6.6) (kernel) RHSA-2017:1798 2017-07-24
Red Hat Enterprise Linux for Real Time for NFV (v. 7) (kernel-rt) RHSA-2017:1616 2017-06-28
Red Hat Enterprise Linux 7 (kernel) RHSA-2017:1615 2017-06-28
Red Hat Enterprise Linux Long Life (v. 5.9 server) (kernel) RHSA-2017:2472 2017-08-15
Red Hat Enterprise Linux Advanced Update Support 6.4 (kernel) RHSA-2017:1715 2017-07-11
Red Hat Enterprise Linux 6 (kernel) RHSA-2017:1723 2017-07-11
Red Hat Enterprise Linux Server TUS (v. 6.5) (kernel) RHSA-2017:2428 2017-08-08
Red Hat Enterprise Linux Extended Update Support 7.2 (kernel) RHSA-2017:1766 2017-07-18
Red Hat Enterprise Linux Advanced Update Support 6.5 (kernel) RHSA-2017:2428 2017-08-08
Red Hat MRG Grid for RHEL 6 Server v.2 (kernel-rt) RHSA-2017:1647 2017-06-28
Red Hat Enterprise Linux Extended Update Support 6.7 (kernel) RHSA-2017:2429 2017-08-08
Red Hat Enterprise Linux Advanced Update Support 6.2 (kernel) RHSA-2017:2732 2017-09-14
Red Hat Enterprise Linux Advanced Update Support 6.6 (kernel) RHSA-2017:1798 2017-07-24
Red Hat Enterprise Linux Server (v. 5 ELS) (kernel) RHSA-2017:2412 2017-08-02

Affected Packages State

Platform Package State
Red Hat Enterprise MRG 2 realtime-kernel Affected

Acknowledgements

Red Hat would like to thank Ari Kauppi for reporting this issue.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.