The tpacketrcv function in net/packet/afpacket.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14497.json"
[
{
"digest": {
"line_hashes": [
"8712159496540658583065811870977356918",
"224116344088691733221878384199032235149",
"56179178043892275680941737250855061006",
"313313079571830991609858873039985655154",
"88946397953822149341480051078517209285",
"75756885459823140397004269840984665262",
"233656064640420442211245037210648076609",
"70950556893278908204928425065402290813",
"103573933177646437798231096375818459330",
"147594534350109633055649209302322330802",
"286058768717341856664427597055617792892",
"162478544364728369631117657347157180808",
"229690924929279448841121141326969445126",
"136220007692008916698456919683981842295",
"190755470190847191896602129005145641285",
"102682107320415571994621754201979530070",
"252313229337861510184444031169377813247",
"189515821775840393003596378876256150580",
"282557872804925453968547238200188954228",
"180410678735126609450416321077614855403",
"89968019663451767465392307375468419578",
"172919208304038709225978075815443200082"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/packet/af_packet.c"
},
"signature_type": "Line",
"id": "CVE-2017-14497-07d9675a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@edbd58be15a957f6a760c4a514cd475217eb97fd",
"deprecated": false
},
{
"digest": {
"function_hash": "144302064692276211636209568595742536207",
"length": 5658.0
},
"signature_version": "v1",
"target": {
"file": "net/packet/af_packet.c",
"function": "tpacket_rcv"
},
"signature_type": "Function",
"id": "CVE-2017-14497-ca3bfc96",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@edbd58be15a957f6a760c4a514cd475217eb97fd",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14497.json"
[
{
"digest": {
"line_hashes": [
"8712159496540658583065811870977356918",
"224116344088691733221878384199032235149",
"56179178043892275680941737250855061006",
"313313079571830991609858873039985655154",
"88946397953822149341480051078517209285",
"75756885459823140397004269840984665262",
"233656064640420442211245037210648076609",
"70950556893278908204928425065402290813",
"103573933177646437798231096375818459330",
"147594534350109633055649209302322330802",
"286058768717341856664427597055617792892",
"162478544364728369631117657347157180808",
"229690924929279448841121141326969445126",
"136220007692008916698456919683981842295",
"190755470190847191896602129005145641285",
"102682107320415571994621754201979530070",
"252313229337861510184444031169377813247",
"189515821775840393003596378876256150580",
"282557872804925453968547238200188954228",
"180410678735126609450416321077614855403",
"89968019663451767465392307375468419578",
"172919208304038709225978075815443200082"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/packet/af_packet.c"
},
"signature_type": "Line",
"id": "CVE-2017-14497-2643d0ce",
"source": "https://github.com/torvalds/linux/commit/edbd58be15a957f6a760c4a514cd475217eb97fd",
"deprecated": false
},
{
"digest": {
"function_hash": "144302064692276211636209568595742536207",
"length": 5658.0
},
"signature_version": "v1",
"target": {
"file": "net/packet/af_packet.c",
"function": "tpacket_rcv"
},
"signature_type": "Function",
"id": "CVE-2017-14497-30191f9b",
"source": "https://github.com/torvalds/linux/commit/edbd58be15a957f6a760c4a514cd475217eb97fd",
"deprecated": false
}
]