CVE-2017-18208

MEDIUM

Linux Kernel < 4.14.4 - Infinite Loop

Title source: rule
STIX 2.1

Description

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.

References (16)

Core 16
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:3083
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3619-2/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:2948
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3653-2/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3655-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3655-2/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3653-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3657-1/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:3096
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3619-1/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3967
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:4058
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:4057

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (1)
linux/linux_kernel < 4.14.4
Published Mar 01, 2018
Tracked Since Feb 18, 2026