CVE-2017-16994 EXPLOIT
5.5
MEDIUM · CVSS 3.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.
Scoring
| CVSS | 5.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 2.08% — more likely to be exploited than 81% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-11-27 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| linux | linux kernel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel 4.13 (Debian 9) - Local Privilege Escalation | 2017-12-11 |
| exploit-db | Linux Kernel - 'mincore()' Heap Page Disclosure (PoC) | 2017-12-11 |
| exploit-db | Linux Kernel - 'mincore()' Uninitialized Kernel Heap Page Disclosure | 2017-11-24 |
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=373c4557d2aa362702c4c2d41288fb1e54990b7c
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.2
- http://www.securityfocus.com/bid/101969
- https://access.redhat.com/errata/RHSA-2018:0502
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1431
- https://github.com/torvalds/linux/commit/373c4557d2aa362702c4c2d41288fb1e54990b7c
- https://usn.ubuntu.com/3617-1/
- https://usn.ubuntu.com/3617-2/
- https://usn.ubuntu.com/3617-3/
- https://usn.ubuntu.com/3619-1/
- https://usn.ubuntu.com/3619-2/
- https://usn.ubuntu.com/3632-1/
- https://www.exploit-db.com/exploits/43178/
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=373c4557d2aa362702c4c2d41288fb1e54990b7c
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.2
- http://www.securityfocus.com/bid/101969
- https://access.redhat.com/errata/RHSA-2018:0502
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1431
- https://github.com/torvalds/linux/commit/373c4557d2aa362702c4c2d41288fb1e54990b7c
- https://usn.ubuntu.com/3617-1/
→ the Explorer · watch your stack · NVD