peter bassill · operator
$ cve CVE-2017-16994 JSON

CVE-2017-16994 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS2.08% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2017-11-27
Last modified2026-06-17

Affected (1)

VendorProduct
linuxlinux kernel

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD