PT-2017-14685 · Linux+1 · Linux Kernel+1

Published

2017-08-30

·

Updated

2023-01-19

·

CVE-2017-17052

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.12.10
Description A local attacker can achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program due to the mm init function in kernel/fork.c not clearing the ->exe file member of a new process's mm struct.
Recommendations For Linux kernel versions prior to 4.12.10, update to version 4.12.10 or later to resolve the issue.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2130
ALT-PU-2017-2131
CVE-2017-17052

Affected Products

Alt Linux
Linux Kernel