Integer overflow in Debian Linux - CVE-2017-17854

 

Integer overflow in Debian Linux - CVE-2017-17854

Published: December 27, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU37734
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17854
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmetic.


Affected software

Debian Linux
Arch Linux
Fedora
kernel

How to mitigate CVE-2017-17854

Install update from vendor's website.

kernel - addressed in versions 4.14.11-200.fc26, 4.14.11-300.fc27

External References

Related Security Bulletins