The 2017 Pwnie Nominee For Best Privilege Escalation Bug

xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window

Credit: slipper from ChaitinTech

At this year’s Pwn2Own, a fully patched Ubuntu desktop was compromised via this Linux privilege escalation showing that even Slashdot readers aren’t safe from staged exploit contests.

xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window (CVE-2017-7184)