Main
Vulnerability Database
Exploits
ID:6339 - Exploit for Out-of-bounds read in Linux kernel - CVE-2017-18344
ID:6339 - Exploit for Out-of-bounds read in Linux kernel - CVE-2017-18344
Published: June 17, 2021
Vulnerability identifier: #VU14184
Vulnerability risk: Low
CVE-ID: CVE-2017-18344
CWE-ID: CWE-125
Exploitation vector: Local access
Vulnerable software:
Linux kernel
Linux kernel
Link to public exploit:
Vulnerability description
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to out-of-bounds memory read error in the 'sigevent->sigev_notify' field of show_timer() function in the timer subsystem. A local attacker can obtain potentially sensitive information from system memory.
Remediation
Update to version 4.14.8.