VDB

CVE-2017-17806

CVE-2017-17806 PUBLISHED

The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.

EPSS 0.01% · 3.0th percentile

Risk Scores

EPSS Score
0.01%
3.0th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSlinux-azure-6.110, *, *
Ubuntu:14.04:LTSlinux-aws4.4.0-1006.6, 4.4.0-1002.2, 0
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:14.04:LTSlinux3.13.0-15.35, 0, 3.11.0-12.19
Ubuntu:16.04:LTSlinux-oem4.13.0-1017.18, 4.13.0-1020.21, 4.13.0-1021.23
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1012.12, 4.4.0-1013.14, 4.4.0-1013.15
Ubuntu:16.04:LTSlinux-aws4.4.0-1035.44, 0, 4.4.0-1001.10
Ubuntu:20.04:LTSlinux-riscv5.4.0-40.45, 5.4.0-34.38, 5.4.0-33.37
Ubuntu:24.04:LTSlinux-lowlatency-hwe-6.11*, 6.11.0-1016.17~24.04.1, 6.11.0-1014.15~24.04.1
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.155.15.0-1058.66~20.04.2.1, 5.15.0-1057.65~20.04.1.1, 5.15.0-1053.61~20.04.1.1
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.3.0-1015.17, 5.4.0-1004.4
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-53.74~14.04.1, 0, 4.4.0-14.30~14.04.2
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:16.04:LTSlinux-hwe4.10.0-35.39~16.04.1, *, 0
Ubuntu:24.04:LTSlinux-hwe-6.116.11.0-29.29~24.04.1, 6.11.0-28.28~24.04.1, 6.11.0-26.26~24.04.1
Ubuntu:16.04:LTSlinux-raspi24.4.0-1069.77, 4.4.0-1070.78, 4.4.0-1071.79
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1005.5, 4.4.0-1003.3, 0
Ubuntu:22.04:LTSlinux-riscv5.15.0-1006.6, 5.15.0-1018.21, 5.15.0-1004.4
Ubuntu:16.04:LTSlinux4.4.0-47.68, 4.4.0-2.16, 4.4.0-24.43
Ubuntu:16.04:LTSlinux-azure4.13.0-1011.14, 4.11.0-1016.16, 4.11.0-1011.11

…and 6 more

Timeline

  • Dec 20, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›