{"id":"MGASA-2017-0158","summary":"Updated libnl3 packages fix security vulnerability","details":"An elevation of privilege vulnerability in the libnl library could enable\na local malicious application to execute arbitrary code within the context\nof a privileged process (CVE-2017-0386).\n\nAn integer overflow vulnerability was found in nlmsg_reserve() triggered\nby crafted @len argument resulting into reserving too few bytes\n(CVE-2017-0553).\n","modified":"2026-04-16T06:24:22.751246958Z","published":"2017-06-08T21:39:47Z","upstream":["CVE-2017-0386","CVE-2017-0553"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0158.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=20168"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JR5R2FSPYCLDAHTXQC2LKY74N5YW2PQQ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KIHASXRQO2YTQPKVP4VGIB2XHPANG6YX/"}],"affected":[{"package":{"name":"libnl3","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/libnl3?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.25-3.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0158.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}