RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1, 8.2
CVE-2017-2636
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
CVSS v3 Base Score: 7.8 High
Security Alert (A17-03-05): Vulnerability in Linux Kernel
Affected Systems:
- Linux Operating System (on 32-bit and 64-bit) based on kernel 4.10.1 and earlier versions
Summary:
A local privilege escalation vulnerability is found in the Linux kernel 4.10.1 and earlier versions. The vulnerability is caused by a race condition flaw in the kernel driver. A local attacker may leverage this vulnerability in the affected systems to gain root privileges.
Impact:
Successful exploitation could lead to denial of service, elevation of privilege or compromise of a vulnerable system.
Recommendation:
The vulnerability is fixed in some of the Linux distributions. Linux system administrators should check with their product vendors to confirm if their Linux systems are affected and the availability of patches, and if so, upgrade to the fixed versions or follow the recommendations provided by the product vendors to mitigate the risk.
DITSOs (or your delegates) are also requested to inform relevant system administrators as appropriate about this issue.
More Information:
Response: The flaw exists but does not add additional risk.
This vulnerability allows an escalation of privilege for local, unprivileged users. The RSA Authentication Manager 8.x Appliance has only a single user with access to logon to the system and this user already has access to full system root privileges.
Related Articles
Linux Kernel vulnerability CVE-2017-17806 on RSA Appliance 3Number of Views DSA-2019-062: RSA Authentication Manager Security Update for Linux Kernel Vulnerabilities 3Number of Views RSA Authentication Manager 8.2 SP1 Vulnerabilities in the Linux kernel – False Positive 4Number of Views Multiple Linux Kernel related vulnerabilities in Authentication Manager 8.1 SP1 P10 or later - False Positives 35Number of Views How do you merge FSM audit logs? 1Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators