ZeroHour

CVE-2017-18017

CVSS 3.1
9.8 critical
EPSS
53%p99
Published
()
Modified
Description

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.

Vendors
linuxdebianaristaf5suseopensuseopenstackcanonicalredhat
Products
linux kernel, debian linux, eos, arx, caas platform, linux enterprise debuginfo, linux enterprise module for public cloud, linux enterprise point of sale, openstack cloud, leap, linux enterprise desktop, linux enterprise high availability
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.