The _ip6appenddata function in net/ipv6/ip6output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9242.json"
[
{
"digest": {
"function_hash": "263087437580517894265538827438967150332",
"length": 5854.0
},
"signature_version": "v1",
"target": {
"file": "net/ipv6/ip6_output.c",
"function": "__ip6_append_data"
},
"signature_type": "Function",
"id": "CVE-2017-9242-08fa571b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@232cd35d0804cc241eb887bb8d4d9b3b9881c64a",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"282606553180901273389935419465463021385",
"276782847656771966132798263861060851463",
"332904380099562348847339223693216578305",
"46350051056219736413724700677776937354",
"65138946690239027255896050587860449755",
"199277539565263796345888809860723814623",
"51242721319121969302080788161506912814",
"330675867740225719700861240952562283171",
"79835428167543279469607136898294147985",
"27753945058434068375801036742421412321",
"644443717943713678089549115749931686",
"151473295816454863567185464964176811549"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"signature_type": "Line",
"id": "CVE-2017-9242-3eaa05f7",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@232cd35d0804cc241eb887bb8d4d9b3b9881c64a",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9242.json"
[
{
"digest": {
"function_hash": "263087437580517894265538827438967150332",
"length": 5854.0
},
"signature_version": "v1",
"target": {
"file": "net/ipv6/ip6_output.c",
"function": "__ip6_append_data"
},
"signature_type": "Function",
"id": "CVE-2017-9242-1629172f",
"source": "https://github.com/torvalds/linux/commit/232cd35d0804cc241eb887bb8d4d9b3b9881c64a",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"282606553180901273389935419465463021385",
"276782847656771966132798263861060851463",
"332904380099562348847339223693216578305",
"46350051056219736413724700677776937354",
"65138946690239027255896050587860449755",
"199277539565263796345888809860723814623",
"51242721319121969302080788161506912814",
"330675867740225719700861240952562283171",
"79835428167543279469607136898294147985",
"27753945058434068375801036742421412321",
"644443717943713678089549115749931686",
"151473295816454863567185464964176811549"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/ipv6/ip6_output.c"
},
"signature_type": "Line",
"id": "CVE-2017-9242-b0ab6d91",
"source": "https://github.com/torvalds/linux/commit/232cd35d0804cc241eb887bb8d4d9b3b9881c64a",
"deprecated": false
}
]