CVE-2017-5897
9.8
CRITICAL · CVSS 3.1 · EPSS 5.6% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.58% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-125 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-03-23 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| linux | linux kernel |
References
- http://www.debian.org/security/2017/dsa-3791
- http://www.openwall.com/lists/oss-security/2017/02/07/2
- http://www.securityfocus.com/bid/96037
- http://www.securitytracker.com/id/1037794
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=7892032cfe67f4bde6fc2ee967e45a8fbaf33756
- https://source.android.com/security/bulletin/2017-09-01
- https://usn.ubuntu.com/3754-1/
- http://www.debian.org/security/2017/dsa-3791
- http://www.openwall.com/lists/oss-security/2017/02/07/2
- http://www.securityfocus.com/bid/96037
- http://www.securitytracker.com/id/1037794
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=7892032cfe67f4bde6fc2ee967e45a8fbaf33756
- https://source.android.com/security/bulletin/2017-09-01
- https://usn.ubuntu.com/3754-1/
→ the Explorer · watch your stack · NVD