PT-2017-3622 · Linux+1 · Linux Kernel+1

Published

2017-11-29

·

Updated

2023-06-21

·

CVE-2017-18202

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.14.4
Description: The issue is related to the oom reap task mm function in mm/oom kill.c, which mishandles gather operations. This can allow attackers to cause a denial of service, such as a TLB entry leak or use-after-free, or possibly have other unspecified impacts. The exploitation involves triggering a copy to user call within a certain time window.
Recommendations: For Linux kernel versions prior to 4.14.4, update to version 4.14.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the copy to user function to minimize the risk of exploitation.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2771
ALT-PU-2017-2789
BDU:2018-00614
CVE-2017-18202
RHSA-2018:2772

Affected Products

Alt Linux
Linux Kernel