CVE-2017-18270 PUBLISHED

In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.

EPSS 0.07% · 22.1th percentile

Risk Scores

EPSS Score
0.07%
22.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-gke5.4.0-1039.41, 5.4.0-1098.105, 5.4.0-1063.66
Ubuntu:16.04:LTSlinux-aws4.4.0-1004.13, 4.4.0-1032.41, 0
Ubuntu:22.04:LTSlinux-riscv5.13.0-1004.4, 5.15.0-1005.5, 0
Ubuntu:14.04:LTSlinux3.13.0-86.130, 3.13.0-119.166, 3.13.0-121.170
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1073.78, 4.4.0-1048.52, 4.4.0-1013.14
Ubuntu:20.04:LTSlinux-raspi25.3.0-1007.8, 5.4.0-1006.6, 5.4.0-1004.4
Ubuntu:20.04:LTSlinux-riscv5.4.0-34.38, 5.4.0-36.41, 5.4.0-37.42
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1068.71+cvm1.1, 5.4.0-1063.66+cvm2.2, 5.4.0-1063.66+cvm3.2
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:16.04:LTSlinux-azure4.11.0-1009.9, 4.11.0-1014.14, 4.11.0-1015.15
Ubuntu:16.04:LTSlinux-raspi24.4.0-1017.23, 4.2.0-1013.19, 4.4.0-1021.27
Ubuntu:16.04:LTSlinux-gcp4.10.0-1009.9, 4.10.0-1007.7, 4.10.0-1006.6
Ubuntu:16.04:LTSlinux-kvm4.4.0-1007.12, 4.4.0-1004.9, 0
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-87.110~14.04.1, 4.4.0-83.106~14.04.1, *
Ubuntu:16.04:LTSlinux4.3.0-2.11, 4.4.0-38.57, 4.4.0-92.115
Ubuntu:16.04:LTSlinux-hwe4.8.0-41.44~16.04.1, 4.10.0-42.46~16.04.1, 4.13.0-31.34~16.04.1

Timeline

References

Open in Interactive Console →