RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1, 8.2
CVE-2017-2636
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
CVSS v3 Base Score: 7.8 High
Security Alert (A17-03-05): Vulnerability in Linux Kernel
Affected Systems:
- Linux Operating System (on 32-bit and 64-bit) based on kernel 4.10.1 and earlier versions
Summary:
A local privilege escalation vulnerability is found in the Linux kernel 4.10.1 and earlier versions. The vulnerability is caused by a race condition flaw in the kernel driver. A local attacker may leverage this vulnerability in the affected systems to gain root privileges.
Impact:
Successful exploitation could lead to denial of service, elevation of privilege or compromise of a vulnerable system.
Recommendation:
The vulnerability is fixed in some of the Linux distributions. Linux system administrators should check with their product vendors to confirm if their Linux systems are affected and the availability of patches, and if so, upgrade to the fixed versions or follow the recommendations provided by the product vendors to mitigate the risk.
DITSOs (or your delegates) are also requested to inform relevant system administrators as appropriate about this issue.
More Information:
Response: The flaw exists but does not add additional risk.
This vulnerability allows an escalation of privilege for local, unprivileged users. The RSA Authentication Manager 8.x Appliance has only a single user with access to logon to the system and this user already has access to full system root privileges.
Related Articles
Radius agent uses old shared secret even after new shared secret is updated in Authentication Manager database 90Number of Views What are the basic requirements for RSA Web Threat Detection to capture our website's traffic? 18Number of Views CyberArk Password Vault Web Access - RADIUS Configuration with Authentication Manager - RSA Ready Implementation Guide 130Number of Views 'Program Error - XC_XParseRegenerateCertificate: [XrcNOTFOUND] unable to locate requested member or object. Can't create i… 38Number of Views Understanding RSA Authentication Manager logging fields when they are forwarded to syslog 597Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Quick Setup Guide - Connect Authentication Manager to Cloud Authentication Service RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager Patch Updates Downloading RSA Authentication Manager license files or RSA Software token seed records