CVE-2017-10661

HIGH

Linux Kernel < 3.2.92 - Use After Free

Title source: rule

Description

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

Exploits (2)

exploitdb WORKING POC
by anonymous · clocallinux
https://www.exploit-db.com/exploits/43345
nomisec WORKING POC 11 stars
by GeneBlue · poc
https://github.com/GeneBlue/CVE-2017-10661_POC

Scores

CVSS v3 7.0
EPSS 0.2570
EPSS Percentile 96.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (7)
debian/debian_linux 8.0
debian/debian_linux 9.0
linux/linux_kernel < 3.2.92
redhat/enterprise_linux 7.0
redhat/enterprise_linux_aus 7.4
redhat/enterprise_linux_server_eus 7.5
redhat/enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 7.4
Published Aug 19, 2017
Tracked Since Feb 18, 2026