CVE-2017-1000365

HIGH

Linux Kernel <4.11.5 - Memory Corruption

Title source: llm
STIX 2.1

Description

The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3927
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99156
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3945
Third Party Advisory, VDB Entry x_refsource_confirm
https://access.redhat.com/security/cve/CVE-2017-1000365

Scores

CVSS v3 7.8
EPSS 0.0090
EPSS Percentile 56.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
linux/linux_kernel 2.6.23 - 3.2.91
Published Jun 19, 2017
Tracked Since Feb 18, 2026