FlawAtlas
Search the atlas
UBUNTU-CVE-2017-17864 Low

UBUNTU-CVE-2017-17864

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."

Exploit probability Not scored
Published December 27, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux-azure
Ubuntu:16.04:LTS linux-azure

15 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

15 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

34 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3523-1
related USN-3523-3

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-17864

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."

View original source

05 / REFERENCES

Further evidence