CVE-2017-17741
Ubuntu Security Notice USN-3620-2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.
La implementación KVM en el kernel de Linux hasta la versión 4.14.7 permite que atacantes remotos obtengan información potencialmente sensible de la memoria del kernel. Esto también se conoce como una lectura fuera de límites basada en pila write_mmio y está relacionado con arch/x86/kvm/x86.c e include/trace/events/kvm.h.
It was discovered that the netlink 802.11 configuration interface in the Linux kernel did not properly validate some attributes passed from userspace. A local attacker with the CAP_NET_ADMIN privilege could use this to cause a denial of service or possibly execute arbitrary code. It was discovered that a buffer overflow existed in the ioctl handling code in the ISDN subsystem of the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-03 CVE Published
- 2017-12-18 CVE Reserved
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102227 | Vdb Entry | |
https://lists.debian.org/debian-lts-announce/2018/01/msg00004.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.spinics.net/lists/kvm/msg160796.html | 2018-04-25 |
URL | Date | SRC |
---|---|---|
https://usn.ubuntu.com/3617-1 | 2018-04-25 | |
https://usn.ubuntu.com/3617-2 | 2018-04-25 | |
https://usn.ubuntu.com/3617-3 | 2018-04-25 | |
https://usn.ubuntu.com/3619-1 | 2018-04-25 | |
https://usn.ubuntu.com/3619-2 | 2018-04-25 | |
https://usn.ubuntu.com/3620-1 | 2018-04-25 | |
https://usn.ubuntu.com/3620-2 | 2018-04-25 | |
https://usn.ubuntu.com/3632-1 | 2018-04-25 | |
https://www.debian.org/security/2017/dsa-4073 | 2018-04-25 | |
https://www.debian.org/security/2018/dsa-4082 | 2018-04-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | <= 4.14.7 Search vendor "Linux" for product "Linux Kernel" and version " <= 4.14.7" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|