CVE-2017-15537 PUBLISHED

The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature, does not correctly handle attempts to set reserved bits in the xstate header via the ptrace() or rt_sigreturn() system call, allowing local users to read the FPU registers of other processes on the system, related to arch/x86/kernel/fpu/regset.c and arch/x86/kernel/fpu/signal.c.

EPSS 0.05% · 14.4th percentile

Risk Scores

EPSS Score
0.05%
14.4th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1067.70+cvm1.1, 5.4.0-1068.71+cvm1.1, 5.4.0-1069.72+cvm1.1
Ubuntu:22.04:LTSlinux-riscv5.15.0-1028.32, 5.15.0-1027.31, 5.15.0-1026.30
Ubuntu:16.04:LTSlinux-azure0, 4.11.0-1014.14, 4.11.0-1013.13
Ubuntu:16.04:LTSlinux-kvm4.4.0-1007.12, 4.4.0-1004.9, 0
Ubuntu:20.04:LTSlinux-gke5.4.0-1053.56, 5.4.0-1052.55, 5.4.0-1051.54
Ubuntu:16.04:LTSlinux-gke4.4.0-1016.16, 4.4.0-1014.14, 4.4.0-1013.13
Ubuntu:16.04:LTSlinux-raspi24.4.0-1067.75, 4.4.0-1075.83, 4.4.0-1074.82
Ubuntu:16.04:LTSlinux-hwe4.10.0-28.32~16.04.2, 4.10.0-30.34~16.04.1, 4.10.0-32.36~16.04.1
Ubuntu:16.04:LTSlinux-aws4.4.0-1016.25, 4.4.0-1013.22, 4.4.0-1012.21
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1007.8, 5.3.0-1014.16
Ubuntu:16.04:LTSlinux4.4.0-28.47, 4.4.0-22.40, 4.4.0-22.39
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:16.04:LTSlinux-gcp4.10.0-1008.8, 4.10.0-1009.9, 4.10.0-1004.4
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1054.58, 4.4.0-1013.15, 4.4.0-1015.18
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-83.106~14.04.1, 4.4.0-79.100~14.04.1, 4.4.0-78.99~14.04.2
Ubuntu:20.04:LTSlinux-riscv0, 5.4.0-24.28, 5.4.0-26.30
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75

Timeline

References

Open in Interactive Console →