Buffer overflow in Debian Linux - CVE-2017-17855
Published: December 27, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU37735
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17855
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging improper use of pointers in place of scalars.
Affected software
Debian Linux
Arch Linux
Fedora
kernel
Arch Linux
Fedora
kernel
How to mitigate CVE-2017-17855
Install update from vendor's website.
kernel - addressed in versions 4.14.11-200.fc26, 4.14.11-300.fc27