peter bassill · operator
$ cve CVE-2017-10661 JSON

CVE-2017-10661 EXPLOIT

7.0
HIGH · CVSS 3.1 · EPSS 13.4% (pctl 96)

Patch early

A public exploit exists.

Description

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

Scoring

CVSS7.0 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS13.38% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploityes
Published2017-08-19
Last modified2026-06-17

Affected (6)

VendorProduct
debiandebian linux
linuxlinux kernel
redhatenterprise linux
redhatenterprise linux aus
redhatenterprise linux server eus
redhatenterprise linux server for power little endian update services for sap solutions

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD