5.5
CVSSv3

CVE-2017-17862

Published: 27/12/2017 Updated: 07/04/2018
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 437
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

kernel/bpf/verifier.c in the Linux kernel up to and including 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

debian debian linux 9.0

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks CVE-2017-8824 Mohamed Ghannam discovered that the DCCP implementation did not correctly manage resources when a socket is disconnected and reconnected, potentially leading to a use-after-free ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
kernel/bpf/verifierc in the Linux kernel through 4148 ignores unreachable code, even though it would still be processed by JIT compilers This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service ...
It has been discovered that kernel/bpf/verifierc in the Linux kernel before 4149 and 4972 ignore unreachable code, even though it would still be processed by JIT compilers This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service ...