CVE-2017-17854

HIGH

Linux Kernel < 4.14.9 - Integer Overflow in BPF Verifier

Title source: llm
STIX 2.1

Description

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmetic.

Scores

CVSS v3 7.8
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (2)
debian/debian_linux 9.0
linux/linux_kernel 4.14 - 4.14.9
Published Dec 27, 2017
Tracked Since Feb 18, 2026