CVE-2017-7184 is an out-of-bounds heap-access vulnerability in the Linux kernel XFRM subsystem. Through Linux kernel 4.10.6, the replay-length verification logic does not validate certain size data supplied in an XFRM_MSG_NEWAE update. A privileged local caller can provide malformed update data that causes heap memory to be accessed outside its allocated bounds.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single C file (`exploit.c`) implementing a proof-of-concept trigger for CVE-2017-7184 in the Linux kernel XFRM/IPsec subsystem. Structure/purpose: - `create_netlink_socket()`: opens/binds a NETLINK_XFRM socket to talk to the kernel XFRM subsystem. - `create_raw_socket()`: opens an IPv4 raw socket for `IPPROTO_AH` to send an Authentication Header packet. - `create_base_sa()`: sends `XFRM_MSG_NEWSA` to create an AH transport-mode Security Association with ESN enabled (`XFRM_STATE_ESN`) and a small replay window. - `send_malicious_update()`: sends `XFRM_MSG_NEWAE` with a crafted `xfrm_replay_state_esn` attribute where `replay_window` is set to `REPLAY_WINDOW_OVERFLOW` (2048), intended to induce an out-of-bounds condition in kernel replay/bitmap handling. - `trigger_oob_write()`: crafts a 1024-byte IPv4 packet containing an AH header with the target SPI and a sequence number `0x80000000` (commented as the trigger for an out-of-bounds index), then `sendto()` to a hardcoded destination. Capabilities/impact: - Provides a local kernel memory corruption trigger path (netlink configuration + raw packet) that may crash the kernel (explicitly warns about kernel panic) and could be a building block for LPE, but it does not include any privilege escalation, ROP chain, or post-exploitation payload. Operational notes: - Requires elevated capabilities (CAP_NET_ADMIN and CAP_NET_RAW) to create/update XFRM SAs and send raw AH packets; therefore it is not a typical unprivileged LPE as written, but a privileged trigger/DoS-style PoC for the vulnerable code path.
Repository purpose: a local Linux kernel privilege-escalation proof-of-concept for CVE-2017-7184 (XFRM/IPsec netlink stack overflow) that aims to obtain real root without sudo by leveraging unprivileged user namespaces. Structure: - CVE-2017-7184_exploit.c: Main exploit program in C. - setup_namespace(): calls unshare(CLONE_NEWUSER|CLONE_NEWNET), writes /proc/self/uid_map, /proc/self/setgroups, /proc/self/gid_map to map the current user to UID/GID 0 inside the namespace, thereby gaining CAP_NET_ADMIN in the new network namespace. - leak_kernel_addresses(): attempts to read /proc/kallsyms to locate commit_creds and prepare_kernel_cred; if restricted, falls back to hardcoded addresses for a specific kernel build (notably 4.8.0-36-generic per README/comments). - save_state(): saves userland CPU state (cs/ss/rsp/rflags) for returning from kernel context. - trigger_exploit(): (partially truncated in provided content) creates a NETLINK_XFRM socket and sends malformed XFRM netlink messages (README mentions XFRM_MSG_NEWSA with oversized attributes) to trigger the kernel stack overflow and execute a kernel ROP chain that calls prepare_kernel_cred(NULL) and commit_creds(). - spawn_root_shell(): verifies UID==0 and execve()s /bin/bash -i. - README.md: High-level explanation, requirements (vulnerable kernel <=4.8, unprivileged_userns_clone enabled), compilation/execution instructions, and limitations (kernel-specific gadgets/offsets, no robust KASLR/SMEP/SMAP bypass). Capabilities and impact: - Local privilege escalation from unprivileged user to real root (UID 0) by exploiting the kernel XFRM netlink stack overflow. - Uses namespace setup as a prerequisite to obtain CAP_NET_ADMIN without sudo, enabling access to the XFRM netlink interface needed to reach the vulnerable code path. Notable observables/fingerprintable targets: - Writes to /proc/self/{uid_map,gid_map,setgroups} (namespace mapping behavior). - Reads /proc/kallsyms for symbol resolution. - Uses NETLINK_XFRM (protocol 6) AF_NETLINK socket. - Spawns /bin/bash on success. Assessment: - Appears to be a real exploit PoC (not just detection). However, it is kernel-build specific (hardcoded addresses/ROP details) and the provided content indicates parts of trigger_exploit are truncated; reliability across kernels is limited, consistent with a PoC maturity level.
This repository contains a local privilege escalation exploit targeting the Linux kernel (version 4.4.20, as indicated by the QEMU run script). The main exploit logic is in exp.c, which manipulates XFRM (IPsec) netlink interfaces and raw sockets to trigger a vulnerability, likely in the kernel's XFRM/ESP/AH handling. The exploit forks a large number of processes to increase the chance of success, and upon successful exploitation, it creates a setuid-root shell at /tmp/bash (compiled from bash.c) and executes it, granting the attacker a root shell. The run.sh script is provided to launch a QEMU VM with the appropriate kernel and disk image for testing. The exploit is operational, providing a working root shell payload, but is not part of a framework and requires manual setup and execution. Notable fingerprintable endpoints include /tmp/bash, /tmp/exploit, and the use of 127.0.0.1 for local socket operations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.