CVE-2017-5123 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 3.7% (pctl 89)
Patch early
A public exploit exists.
Description
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 3.71% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-11-02 |
| Last modified | 2026-06-17 |
Affected (16)
| Vendor | Product |
|---|---|
| linux | linux kernel |
| netapp | cloud backup |
| netapp | h300e |
| netapp | h300e firmware |
| netapp | h300s |
| netapp | h300s firmware |
| netapp | h410s |
| netapp | h410s firmware |
| netapp | h500e |
| netapp | h500e firmware |
| netapp | h500s |
| netapp | h500s firmware |
| netapp | h700e |
| netapp | h700e firmware |
| netapp | h700s |
| netapp | h700s firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel 4.13 (Ubuntu 17.10) - 'waitid()' SMEP/SMAP/Chrome Sandbox Privilege Escalation | 2017-11-06 |
| exploit-db | Linux Kernel 4.14.0-rc4+ - 'waitid()' Local Privilege Escalation | 2017-10-22 |
References
- https://crbug.com/772848
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=96ca579a1ecc943b75beba58bebb0356f6cc4b51
- https://security.netapp.com/advisory/ntap-20211223-0003/
- https://crbug.com/772848
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=96ca579a1ecc943b75beba58bebb0356f6cc4b51
- https://security.netapp.com/advisory/ntap-20211223-0003/
→ the Explorer · watch your stack · NVD