7.1
CVSSv3

CVE-2017-11472

Published: 20/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel prior to 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel up to and including 4.9) via a crafted ACPI table.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
The acpi_ns_terminate() function in drivers/acpi/acpica/nsutilsc in the Linux kernel before 412 does not flush the operand cache and causes a kernel stack dump A local users could obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 49) via a crafted ACPI table ...