CVE-2017-1000111: Debian Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Linux Linux Kernel: from 2.6.27, before 3.2.92 (fixed in 3.2.92); from 3.3, before 3.10.108 (fixed in 3.10.108); from 3.11, before 3.16.47 (fixed in 3.16.47); from 3.17, before 3.18.65 (fixed in 3.18.65); from 3.19, before 4.1.44 (fixed in 4.1.44); from 4.2, before 4.4.82 (fixed in 4.4.82); …
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.4 only; version 7.5 only; version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2017-10-05. Last modified 2026-06-17.