---
cve: "CVE-2017-7308"
severity: "LOW"
cvss: 3.1
epss: "17.8%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-03-29 20:59:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T17:07:55+02:00"
---

# CVE-2017-7308

> 3.1 LOW · 🧪 PoC

## Beschreibung

The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.

## Exploit-Evidenz

- [EDB-44654 — Linux 4.8.0 < 4.8.0-46 - AF_PACKET packet_set_ring Privilege Escalation (Metasploit)](https://www.exploit-db.com/exploits/44654) ✅
- [EDB-41994 — Linux Kernel 4.8.0-41-generic (Ubuntu) - Packet Socket Local Privilege Escalation](https://www.exploit-db.com/exploits/41994) ✅
- [EDB-47168 — Linux Kernel 4.8.0-34 < 4.8.0-45 (Ubuntu / Linux Mint) - Packet Socket Local Privilege Escalation](https://www.exploit-db.com/exploits/47168)

## Referenzen

- <https://access.redhat.com/errata/RHSA-2017:1308>
- <https://googleprojectzero.blogspot.com/2017/05/exploiting-linux-kernel-via-packet.html>
- <https://source.android.com/security/bulletin/2017-07-01>
- <https://access.redhat.com/errata/RHSA-2018:1854>
- <http://www.securityfocus.com/bid/97234>
- <https://patchwork.ozlabs.org/patch/744812/>
- <https://www.exploit-db.com/exploits/41994/>
- <https://patchwork.ozlabs.org/patch/744813/>
- <https://www.exploit-db.com/exploits/44654/>
- <https://patchwork.ozlabs.org/patch/744811/>
- <https://access.redhat.com/errata/RHSA-2017:1298>
- <https://access.redhat.com/errata/RHSA-2017:1297>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-7308) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
