CVE-2017-2618

MEDIUM

Linux Kernel <4.9.10 - Use After Free

Title source: llm

Description

A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-682 CWE-193
Status published

Affected Products (11)

linux/linux_kernel < 4.9.10
debian/debian_linux
redhat/enterprise_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_server_eus
redhat/enterprise_linux_server_eus
redhat/enterprise_linux_server_eus
redhat/enterprise_linux_workstation

Timeline

Published Jul 27, 2018
Tracked Since Feb 18, 2026