CVE Database
/

CVE-2017-1000370

Back to search

CVE-2017-1000370

Published: Jun 19, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.

VendorProductVersions

n/a

n/a

affected
n/a

References

99149
vdb-entry
x_refsource_BID
DSA-3981
vendor-advisory
x_refsource_DEBIAN
42273
exploit
x_refsource_EXPLOIT-DB
42274
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now