CVE-2017-14954 REJECTED

The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call.

EPSS 0.97% · 76.6th percentile

Risk Scores

EPSS Score
0.97%
76.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-azure4.11.0-1016.16, 0, 4.11.0-1009.9
Ubuntu:14.04:LTSlinux-azure0
Ubuntu:16.04:LTSlinux-hwe4.8.0-45.48~16.04.1, 4.10.0-32.36~16.04.1, 4.10.0-33.37~16.04.1
Ubuntu:16.04:LTSlinux-oem0
Ubuntu:16.04:LTSlinux-gcp4.10.0-1006.6, 4.10.0-1007.7, 4.10.0-1004.4

Timeline

References

Open in Interactive Console →