CVE Database
/

CVE-2017-7495

Back to search

CVE-2017-7495

Published: May 15, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.

VendorProductVersions

n/a

Linux kernel before 4.6.2

affected
Linux kernel before 4.6.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now