Buffer overflow in Debian Linux - CVE-2017-17855

 

Buffer overflow in Debian Linux - CVE-2017-17855

Published: December 27, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU37735
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17855
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging improper use of pointers in place of scalars.


Affected software

Debian Linux
Arch Linux
Fedora
kernel

How to mitigate CVE-2017-17855

Install update from vendor's website.

kernel - addressed in versions 4.14.11-200.fc26, 4.14.11-300.fc27

External References

Related Security Bulletins