CVE-2017-17854

HIGH

Linux Kernel < 4.14.9 - Integer Overflow

Title source: rule
STIX 2.1

Description

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmetic.

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 31.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (2)
debian/debian_linux 9.0
linux/linux_kernel 4.14 - 4.14.9
Published Dec 27, 2017
Tracked Since Feb 18, 2026