FlawAtlas
Search the atlas
UBUNTU-CVE-2017-5550 Moderate

UBUNTU-CVE-2017-5550

Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision.

Exploit probability Not scored
Published February 6, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux-azure
Ubuntu:16.04:LTS linux-azure
Ubuntu:16.04:LTS linux-gcp
Ubuntu:16.04:LTS linux-hwe

14 explicit affected versions

Ubuntu:16.04:LTS linux-oem
Ubuntu:18.04:LTS linux
Ubuntu:18.04:LTS linux-aws
Ubuntu:18.04:LTS linux-azure
Ubuntu:18.04:LTS linux-gcp
Ubuntu:18.04:LTS linux-kvm
Ubuntu:18.04:LTS linux-oem
Ubuntu:18.04:LTS linux-raspi2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-5550

Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision.

View original source

05 / REFERENCES

Further evidence