### [CVE-2017-16939](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16939) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/Al1ex/LinuxEelvation - https://github.com/De4dCr0w/Linux-kernel-EoP-exp - https://github.com/JlSakuya/Linux-Privilege-Escalation-Exploits - https://github.com/Micr067/linux-kernel-exploits - https://github.com/QChiLan/linux-exp - https://github.com/R0B1NL1N/Linux-Kernal-Exploits-m- - https://github.com/SecWiki/linux-kernel-exploits - https://github.com/Snoopy-Sec/Localroot-ALL-CVE - https://github.com/ZTK-009/linux-kernel-exploits - https://github.com/albinjoshy03/linux-kernel-exploits - https://github.com/alian87/linux-kernel-exploits - https://github.com/distance-vector/linux-kernel-exploits - https://github.com/fei9747/LinuxEelvation - https://github.com/hktalent/bug-bounty - https://github.com/kumardineshwar/linux-kernel-exploits - https://github.com/ozkanbilge/Linux-Kernel-Exploits - https://github.com/password520/linux-kernel-exploits - https://github.com/qiantu88/Linux--exp - https://github.com/rakjong/LinuxElevation - https://github.com/xfinest/linux-kernel-exploits - https://github.com/xssfile/linux-kernel-exploits - https://github.com/yige666/linux-kernel-exploits - https://github.com/zyjsuper/linux-kernel-exploits