PT-2017-13274 · Linux+5 · Linux Kernel+5

Otto Ebeling

·

Published

2017-08-27

·

Updated

2018-07-09

·

CVE-2017-14140

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.12.9
Description The issue allows a local attacker to learn the memory layout of a setuid executable despite Address Space Layout Randomization (ASLR). This is due to the move pages system call not checking the effective uid of the target process.
Recommendations For Linux kernel versions prior to 4.12.9, update to version 4.12.9 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2114
ALT-PU-2018-1991
CESA-2018_1062
CVE-2017-14140
DLA-1099-1
DSA-3981-1
RHSA-2018:0676
RHSA-2018:1062
RHSA-2018_0676
RHSA-2018_1062
SUSE-SU-2017:2694-1
SUSE-SU-2017:2908-1
SUSE-SU-2017:2920-1
SUSE-SU-2017:3265-1
SUSE-SU-2018:0040-1
USN-3444-1
USN-3444-2
USN-3583-1
USN-3583-2

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu