A reference counter leak in ipxitf_ioctl function was found which results into use after free vulnerability that's triggerable from unprivileged userspace when IPX interface is configured. References: http://seclists.org/oss-sec/2017/q2/251 https://patchwork.ozlabs.org/patch/757549/ Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ee0d8d8482345ff97a75a7d747efc309f13b0d80
Acknowledgments: Name: Li Qiang (Qihoo 360)
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1450417]
Statement: This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 as the code with the flaw is not shipped with the products listed.