VYPR
Unrated severityNVD Advisory· Published Feb 2, 2018· Updated Sep 16, 2024

CVE-2017-14179

CVE-2017-14179

Description

Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Apport before 2.13 mishandles crashes from PID namespaces, letting local attackers create files as root, enabling DoS, privilege escalation, or container escape.

Vulnerability

Apport versions before 2.13 do not properly handle crashes originating from a PID namespace. This allows a local user to create certain files as root without proper access controls. The vulnerability affects all supported Ubuntu releases up to 17.10 and potentially other distributions using Apport. [1][2]

Exploitation

An attacker with local access to a system using Apport can trigger a crash in a PID namespace (e.g., inside a container) and cause Apport to write crash reports or other files as root. The attacker can manipulate the crash data to exhaust disk space (denial of service) or overwrite sensitive files such as setuid binaries or system configuration to escalate privileges or escape a container. [2]

Impact

Successful exploitation can lead to denial of service via full disk exhaustion, local privilege escalation to root, or container escape. An attacker may gain complete control over the host system or cause persistent service disruption. [1][2]

Mitigation

Upgrade Apport to version 2.13 or later, which includes the fix. Ubuntu has released updated packages for supported releases. If an immediate update is not possible, consider disabling Apport or restricting its use in container environments. [1][2]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.