CVE-2017-7533
HIGH IN THE WILDLinux Kernel <4.12.4 - Privilege Escalation
Title source: llmExploitation Summary
CVE-2017-7533 has been observed exploited in the wild (reported by InTheWild.io). EIP tracks 1 public exploit from researchers including Jeremy Huang.
AI-analyzed exploit summary This exploit demonstrates a heap overflow vulnerability in the Linux kernel's inotify subsystem (CVE-2017-7533). It triggers the bug by rapidly renaming and opening files to corrupt kernel memory, potentially allowing privilege escalation.
Description
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneous execution of the inotify_handle_event and vfs_rename functions.
Exploits (1)
This exploit demonstrates a heap overflow vulnerability in the Linux kernel's inotify subsystem (CVE-2017-7533). It triggers the bug by rapidly renaming and opening files to corrupt kernel memory, potentially allowing privilege escalation.
References (20)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H