KernelScan.io

HIGH Public exploit Introduced in 2.6.27

packet RingBlock Overflow

CVE-2017-7308

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.8HIGH

01

The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.

02

Engine v0.6.0

Risk summary

A local attacker with CAP_NET_RAW (obtainable via user namespaces) can exploit an integer signedness error in the AF_PACKET ring buffer setup to achieve an out-of-bounds write, leading to denial of service or privilege escalation. The bug has been exploited in the wild and has public exploits available.

Affectednet/packet/af_packet.c

Vulnerability analysis

When configuring a packet ring buffer, the kernel validates that the requested private data area fits within the allocated block size by subtracting the two unsigned values and casting the result to a signed integer. Because both operands are unsigned, a larger private-area size causes the subtraction to wrap around to a large positive value, bypassing the bounds check and allowing an out-of-bounds write into kernel memory. A secondary overflow can also occur in the macro that adds the private-area size to a header offset. The fix replaces the subtraction-and-cast comparison with a direct unsigned comparison and widens the private-area size to 64 bits before the offset calculation, preventing both overflow paths. The attack surface is local: any user holding CAP_NET_RAW—which unprivileged processes can obtain through user namespaces on many configurations—can trigger this via crafted setsockopt system calls, making it reachable in container and multi-tenant environments.

Exploit availability

KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.

03

BranchIntroducedFixed inPatch commit
3.22.6.273.2.89—
3.102.6.273.10.107—
3.122.6.273.12.74—
3.162.6.273.16.44—
3.182.6.273.18.52—
4.12.6.274.1.41—
4.42.6.274.4.66—
4.92.6.274.9.26—
4.102.6.274.10.14—
mainline2.6.274.11-rc62b6867c2ce76