CVE-2017-2618

MEDIUM

Linux Kernel <4.9.10 - Use After Free

Title source: llm
STIX 2.1

Description

A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-682 CWE-193
Status published
Products (11)
debian/debian_linux 8.0
linux/linux_kernel < 4.9.10
redhat/enterprise_linux 7.0
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_server_aus 7.3
redhat/enterprise_linux_server_aus 7.4
redhat/enterprise_linux_server_eus 7.3
redhat/enterprise_linux_server_eus 7.4
redhat/enterprise_linux_server_eus 7.5
... and 1 more
Published Jul 27, 2018
Tracked Since Feb 18, 2026