FlawAtlas
Search the atlas
UBUNTU-CVE-2017-1000365 High

UBUNTU-CVE-2017-1000365

The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.

Exploit probability Not scored
Published June 19, 2017
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux

117 explicit affected versions

Ubuntu:14.04:LTS linux-lts-xenial

34 explicit affected versions

Ubuntu:16.04:LTS linux

56 explicit affected versions

Ubuntu:16.04:LTS linux-aws

14 explicit affected versions

Ubuntu:16.04:LTS linux-gke

12 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

17 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

32 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

29 explicit affected versions

Ubuntu:20.04:LTS linux-azure-fde

26 explicit affected versions

Ubuntu:20.04:LTS linux-gke

51 explicit affected versions

Ubuntu:20.04:LTS linux-raspi2

6 explicit affected versions

Ubuntu:20.04:LTS linux-riscv

12 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-riscv

23 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3377-1
related USN-3381-2

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-1000365

The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.

View original source

05 / REFERENCES

Further evidence