RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1, 8.2
CVE-2017-2636
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
CVSS v3 Base Score: 7.8 High
Security Alert (A17-03-05): Vulnerability in Linux Kernel
Affected Systems:
- Linux Operating System (on 32-bit and 64-bit) based on kernel 4.10.1 and earlier versions
Summary:
A local privilege escalation vulnerability is found in the Linux kernel 4.10.1 and earlier versions. The vulnerability is caused by a race condition flaw in the kernel driver. A local attacker may leverage this vulnerability in the affected systems to gain root privileges.
Impact:
Successful exploitation could lead to denial of service, elevation of privilege or compromise of a vulnerable system.
Recommendation:
The vulnerability is fixed in some of the Linux distributions. Linux system administrators should check with their product vendors to confirm if their Linux systems are affected and the availability of patches, and if so, upgrade to the fixed versions or follow the recommendations provided by the product vendors to mitigate the risk.
DITSOs (or your delegates) are also requested to inform relevant system administrators as appropriate about this issue.
More Information:
Response: The flaw exists but does not add additional risk.
This vulnerability allows an escalation of privilege for local, unprivileged users. The RSA Authentication Manager 8.x Appliance has only a single user with access to logon to the system and this user already has access to full system root privileges.
Related Articles
RSA Identity Governance and Lifecycle 7.5 Upgrade and Migration Guide 75Number of Views RSA MFA Agent 9.0 for PAM Release Notes (German) 10Number of Views WorkPoint.log and heap dumps are written to the Linux root directory ( / ) on WebSphere and WebLogic implementations of RS… 145Number of Views Authentication Manager Log Messages (16001-16050) 85Number of Views Error "Required data is missing from command" while updating notes in RSA Authentication Manager 8.x Token Management Snap… 80Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026) An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.8 Setup and Configuration Guide