Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perfeventopen system calls for moving a software group into a hardware context. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6001.json"
[
{
"signature_type": "Function",
"target": {
"file": "kernel/events/core.c",
"function": "SYSCALL_DEFINE5"
},
"deprecated": false,
"id": "CVE-2017-6001-267d29f2",
"signature_version": "v1",
"digest": {
"function_hash": "47257360642735380924126011880312366986",
"length": 5043.0
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@321027c1fe77f892f4ea07846aeae08cefbbb290"
},
{
"signature_type": "Line",
"target": {
"file": "kernel/events/core.c"
},
"deprecated": false,
"id": "CVE-2017-6001-8fa964ca",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"317003286487984133387796312165989722136",
"302012380425267447213769528438301640077",
"139857727396732961448830506088431399378",
"108287479677041064462257905060918514069",
"337778751965244114989828964100637073674",
"190033286283900422514339966268848462892",
"205930025389018243285047208605075813235",
"84954529117739799414107413822388136591",
"329200359327056701499106739782563584585",
"152682066514783382112234011354403472037",
"111875052547944216548034796333338040435",
"123270005526364815370647960003221521129",
"303422065773832814608720780627478761058",
"62574365207443976898772123893243165224",
"46724262783774822331674310075686329410",
"95839343922485194327753945628638282020",
"309534745911892869486983090961483159841",
"36889724199920500615391722987727430577",
"207745975770715697812033060216146101724",
"66221871957170956639002852043748541321"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@321027c1fe77f892f4ea07846aeae08cefbbb290"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6001.json"
[
{
"signature_type": "Line",
"target": {
"file": "kernel/events/core.c"
},
"deprecated": false,
"id": "CVE-2017-6001-7955f990",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"317003286487984133387796312165989722136",
"302012380425267447213769528438301640077",
"139857727396732961448830506088431399378",
"108287479677041064462257905060918514069",
"337778751965244114989828964100637073674",
"190033286283900422514339966268848462892",
"205930025389018243285047208605075813235",
"84954529117739799414107413822388136591",
"329200359327056701499106739782563584585",
"152682066514783382112234011354403472037",
"111875052547944216548034796333338040435",
"123270005526364815370647960003221521129",
"303422065773832814608720780627478761058",
"62574365207443976898772123893243165224",
"46724262783774822331674310075686329410",
"95839343922485194327753945628638282020",
"309534745911892869486983090961483159841",
"36889724199920500615391722987727430577",
"207745975770715697812033060216146101724",
"66221871957170956639002852043748541321"
]
},
"source": "https://github.com/torvalds/linux/commit/321027c1fe77f892f4ea07846aeae08cefbbb290"
},
{
"signature_type": "Function",
"target": {
"file": "kernel/events/core.c",
"function": "SYSCALL_DEFINE5"
},
"deprecated": false,
"id": "CVE-2017-6001-7f389157",
"signature_version": "v1",
"digest": {
"function_hash": "47257360642735380924126011880312366986",
"length": 5043.0
},
"source": "https://github.com/torvalds/linux/commit/321027c1fe77f892f4ea07846aeae08cefbbb290"
}
]