Memory corruption in Linux kernel - CVE-2017-16995

 

Memory corruption in Linux kernel - CVE-2017-16995

Published: December 26, 2017 / Updated: June 17, 2021


Vulnerability identifier: #VU9753
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16995
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition or execute arbitrary code on the target system.

The weakness exists in the check_alu_op function due to boundary error. A local attacker can trigger memory corruption, cause the service to crash or execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Linux kernel
Arch Linux
Ubuntu

How to mitigate CVE-2017-16995

Update to version 4.14.9.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins