The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-11176.json"
[
{
"id": "CVE-2017-11176-785c1d29",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f991af3daabaecff34684fd51fac80319d1baad1",
"target": {
"file": "ipc/mqueue.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"69376919815421647557327119914031938492",
"323845028122122371589464191768437143320",
"71451027776802941335195482811562668014",
"309783035366740639175950767952465670767",
"111580484333852601794976578872270818298"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"id": "CVE-2017-11176-98c02e12",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f991af3daabaecff34684fd51fac80319d1baad1",
"target": {
"file": "ipc/mqueue.c",
"function": "do_mq_notify"
},
"digest": {
"function_hash": "135024264354314921712867092466103694154",
"length": 2439.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-11176.json"
[
{
"id": "CVE-2017-11176-38cd7be2",
"source": "https://github.com/torvalds/linux/commit/f991af3daabaecff34684fd51fac80319d1baad1",
"target": {
"file": "ipc/mqueue.c",
"function": "do_mq_notify"
},
"digest": {
"function_hash": "135024264354314921712867092466103694154",
"length": 2439.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2017-11176-a1ca129e",
"source": "https://github.com/torvalds/linux/commit/f991af3daabaecff34684fd51fac80319d1baad1",
"target": {
"file": "ipc/mqueue.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"69376919815421647557327119914031938492",
"323845028122122371589464191768437143320",
"71451027776802941335195482811562668014",
"309783035366740639175950767952465670767",
"111580484333852601794976578872270818298"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
}
]