CVE-2017-7874: Linux Kernel 4.8.0 UDEV < 232 Local Privilege Escalation Vulnerability
by CIRT Team
Description: udevd in udev 232, when the Linux kernel 4.8.0 is used, does not properly verify the source of a Netlink message, which allows local users to execute arbitrary commands by leveraging access to the NETLINK_KOBJECT_UEVENT family, and the presence of the /lib/udev/rules.d/50-udev-default.rules file, to provide a crafted REMOVE_CMD value.
Impact: Local attackers may exploit this issue to execute arbitrary commands with elevated privileges.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
26 Oct 2023 - Security Advisories & Alerts