ID:6339 - Exploit for Out-of-bounds read in Linux kernel - CVE-2017-18344

 
Main Vulnerability Database Exploits ID:6339 - Exploit for Out-of-bounds read in Linux kernel - CVE-2017-18344

ID:6339 - Exploit for Out-of-bounds read in Linux kernel - CVE-2017-18344

Published: June 17, 2021


Vulnerability identifier: #VU14184
Vulnerability risk: Low
CVE-ID: CVE-2017-18344
CWE-ID: CWE-125
Exploitation vector: Local access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to out-of-bounds memory read error in the 'sigevent->sigev_notify' field of show_timer() function in the timer subsystem. A local attacker can obtain potentially sensitive information from system memory.


Remediation

Update to version 4.14.8.