CVE-2017-18255 PUBLISHED

The perf_cpu_time_max_percent_handler function in kernel/events/core.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow) or possibly have unspecified other impact via a large value, as demonstrated by an incorrect sample-rate calculation.

EPSS 0.11% · 29.4th percentile

Risk Scores

EPSS Score
0.11%
29.4th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-gke5.4.0-1090.97, 5.4.0-1095.102, 5.4.0-1094.101
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips0, 4.4.0-1003.3, 4.4.0-1005.5
Ubuntu:16.04:LTSlinux-hwe4.8.0-36.36~16.04.1, 4.13.0-31.34~16.04.1, 4.13.0-26.29~16.04.2
Ubuntu:24.04:LTSlinux-hwe-6.116.11.0-19.19~24.04.1, 6.11.0-21.21~24.04.1, 6.11.0-24.24~24.04.1
Ubuntu:24.04:LTSlinux-lowlatency-hwe-6.116.11.0-1011.12~24.04.1, 6.11.0-1012.13~24.04.1, 6.11.0-1013.14~24.04.1
Ubuntu:22.04:LTSlinux-riscv5.15.0-1016.18, 0, 5.13.0-1004.4
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1051.55, 4.4.0-1050.54, 4.4.0-1048.52
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:16.04:LTSlinux4.4.0-8.23, 4.4.0-9.24, 4.4.0-66.87
Ubuntu:16.04:LTSlinux-raspi24.4.0-1070.78, 4.4.0-1067.75, 4.4.0-1065.73
Ubuntu:16.04:LTSlinux-gcp4.10.0-1004.4, 0, 4.10.0-1009.9
Ubuntu:14.04:LTSlinux3.13.0-115.162, 3.13.0-86.131, 3.13.0-86.130
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:24.04:LTSlinux-azure-6.116.11.0-1012.12~24.04.1, 6.11.0-1018.18~24.04.1, 6.11.0-1017.17~24.04.1
Ubuntu:24.04:LTSlinux-gcp-6.116.11.0-1017.17~24.04.1, 6.11.0-1016.16~24.04.1, 6.11.0-1015.15~24.04.1
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.155.15.0-1049.56~20.04.1.1, 5.15.0-1050.57~20.04.1.1, 5.15.0-1051.59~20.04.1.1
Ubuntu:14.04:LTSlinux-aws4.4.0-1009.9, 4.4.0-1006.6, 4.4.0-1019.19
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.4.0-1004.4, 5.3.0-1017.19
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-62.83~14.04.1, 4.4.0-63.84~14.04.2, 4.4.0-64.85~14.04.1

…and 4 more

Timeline

References

Open in Interactive Console →