HIGH Public exploit Introduced in 2.6.27
packet RingBlock Overflow
CVE-2017-7308
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.8HIGH
01Description
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
02KernelScan AI Analysis
Risk summary
A local attacker with CAP_NET_RAW (obtainable via user namespaces) can exploit an integer signedness error in the AF_PACKET ring buffer setup to achieve an out-of-bounds write, leading to denial of service or privilege escalation. The bug has been exploited in the wild and has public exploits available.
Vulnerability analysis
When configuring a packet ring buffer, the kernel validates that the requested private data area fits within the allocated block size by subtracting the two unsigned values and casting the result to a signed integer. Because both operands are unsigned, a larger private-area size causes the subtraction to wrap around to a large positive value, bypassing the bounds check and allowing an out-of-bounds write into kernel memory. A secondary overflow can also occur in the macro that adds the private-area size to a header offset. The fix replaces the subtraction-and-cast comparison with a direct unsigned comparison and widens the private-area size to 64 bits before the offset calculation, preventing both overflow paths. The attack surface is local: any user holding CAP_NET_RAW—which unprivileged processes can obtain through user namespaces on many configurations—can trigger this via crafted setsockopt system calls, making it reachable in container and multi-tenant environments.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 3.2 | 2.6.27 | 3.2.89 | — |
| 3.10 | 2.6.27 | 3.10.107 | — |
| 3.12 | 2.6.27 | 3.12.74 | — |
| 3.16 | 2.6.27 | 3.16.44 | — |
| 3.18 | 2.6.27 | 3.18.52 | — |
| 4.1 | 2.6.27 | 4.1.41 | — |
| 4.4 | 2.6.27 | 4.4.66 | — |
| 4.9 | 2.6.27 | 4.9.26 | — |
| 4.10 | 2.6.27 | 4.10.14 | — |
| mainline | 2.6.27 | 4.11-rc6 | 2b6867c2ce76 |