CVE-2017-18509: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187.
Affected products
- Canonical Ubuntu Linux: version 16.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Linux Linux Kernel: before 3.16.72 (fixed in 3.16.72); from 3.17, before 4.4.187 (fixed in 4.4.187); from 4.5, before 4.9.187 (fixed in 4.9.187); from 4.10, before 4.11 (fixed in 4.11)
Published 2019-08-13. Last modified 2026-06-17.