Back to search
CVE-2017-17864
Published: Dec 23, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1040059
vdb-entry
x_refsource_SECTRACK
102320
vdb-entry
x_refsource_BID
DSA-4073
vendor-advisory
x_refsource_DEBIAN
USN-3523-2
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now