UBUNTU-CVE-2017-17863
kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly have unspecified other impact.
02 / AFFECTED SOFTWARE
Affected packages
3 explicit affected versions
4 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly have unspecified other impact.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2017/12/24/1
- https://ubuntu.com/security/CVE-2017-17863
- https://ubuntu.com/security/notices/USN-3523-1
- https://ubuntu.com/security/notices/USN-3523-2
- https://ubuntu.com/security/notices/USN-3523-3
- https://www.cve.org/CVERecord?id=CVE-2017-17863
- https://www.spinics.net/lists/stable/msg206985.html