Buffer overflow in Debian Linux - CVE-2017-17857

 

Buffer overflow in Debian Linux - CVE-2017-17857

Published: December 27, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU37737
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17857
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of invalid variable stack read operations.


Affected software

Debian Linux
Arch Linux
Fedora
kernel

How to mitigate CVE-2017-17857

Install update from vendor's website.

kernel - addressed in versions 4.14.11-200.fc26, 4.14.11-300.fc27

External References

Related Security Bulletins