CVE-2017-5550 REJECTED

Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision.

EPSS 0.08% · 23.4th percentile

Risk Scores

EPSS Score
0.08%
23.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-azure0
Ubuntu:16.04:LTSlinux-oem0
Ubuntu:16.04:LTSlinux-gcp0
Ubuntu:16.04:LTSlinux-azure0
Ubuntu:18.04:LTSlinux-gcp0
Ubuntu:18.04:LTSlinux-kvm0
Ubuntu:18.04:LTSlinux0
Ubuntu:16.04:LTSlinux-hwe4.8.0-45.48~16.04.1, 4.8.0-46.49~16.04.1, 4.8.0-49.52~16.04.1
Ubuntu:18.04:LTSlinux-raspi20
Ubuntu:18.04:LTSlinux-aws0
Ubuntu:18.04:LTSlinux-oem0
Ubuntu:18.04:LTSlinux-azure0

Timeline

References

Open in Interactive Console →