peter bassill · operator
$ cve CVE-2017-2671 JSON

CVE-2017-2671 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 1.5% (pctl 73)

Patch early

A public exploit exists.

Description

The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS1.46% — more likely to be exploited than 73% of all CVEs
On CISA KEVno
Public exploityes
Published2017-04-05
Last modified2026-06-17

Affected (1)

VendorProduct
linuxlinux kernel

Public exploits

SourceTitleDate
exploit-dbLinux Kernel - 'ping' Local Denial of Service2017-06-07

References

→ the Explorer  ·  watch your stack  ·  NVD