The ipv4pktinfoprepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options.
[
{
"deprecated": false,
"id": "CVE-2017-5970-06170629",
"digest": {
"line_hashes": [
"299403172319801379264805393795885286703",
"100134460949411236402764988591876346497",
"189591445322757902181011304181069009466",
"267676441129976000533244006760638288687"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/ipv4/ip_sockglue.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@34b2cef20f19c87999fff3da4071e66937db9644",
"signature_type": "Line"
},
{
"deprecated": false,
"id": "CVE-2017-5970-54a90cdf",
"digest": {
"function_hash": "280705847673189205049071687789944815120",
"length": 451.0
},
"signature_version": "v1",
"target": {
"function": "ipv4_pktinfo_prepare",
"file": "net/ipv4/ip_sockglue.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@34b2cef20f19c87999fff3da4071e66937db9644",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5970.json"
[
{
"deprecated": false,
"id": "CVE-2017-5970-4d41f984",
"digest": {
"function_hash": "280705847673189205049071687789944815120",
"length": 451.0
},
"signature_version": "v1",
"target": {
"function": "ipv4_pktinfo_prepare",
"file": "net/ipv4/ip_sockglue.c"
},
"source": "https://github.com/torvalds/linux/commit/34b2cef20f19c87999fff3da4071e66937db9644",
"signature_type": "Function"
},
{
"deprecated": false,
"id": "CVE-2017-5970-960a5a7e",
"digest": {
"line_hashes": [
"299403172319801379264805393795885286703",
"100134460949411236402764988591876346497",
"189591445322757902181011304181069009466",
"267676441129976000533244006760638288687"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/ipv4/ip_sockglue.c"
},
"source": "https://github.com/torvalds/linux/commit/34b2cef20f19c87999fff3da4071e66937db9644",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5970.json"