CVE-2017-1000253

EUVD-2017-1514
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
centoscentos
6.0
centoscentos
6.1
centoscentos
6.2
centoscentos
6.3
centoscentos
6.4
centoscentos
6.5
centoscentos
6.6
centoscentos
6.7
centoscentos
6.8
centoscentos
6.9
centoscentos
7.1406
centoscentos
7.1503
centoscentos
7.1511
centoscentos
7.1611
redhatenterprise_linux
6.0
redhatenterprise_linux
6.1
redhatenterprise_linux
6.2
redhatenterprise_linux
6.3
redhatenterprise_linux
6.4
redhatenterprise_linux
6.5
redhatenterprise_linux
6.6
redhatenterprise_linux
6.7
redhatenterprise_linux
6.8
redhatenterprise_linux
6.9
redhatenterprise_linux
7.0
redhatenterprise_linux
7.1
redhatenterprise_linux
7.2
redhatenterprise_linux
7.3
linuxlinux_kernel
2.6.25 ≤
𝑥
< 3.2.70
linuxlinux_kernel
3.3 ≤
𝑥
< 3.4.109
linuxlinux_kernel
3.5 ≤
𝑥
< 3.10.77
linuxlinux_kernel
3.11 ≤
𝑥
< 3.12.43
linuxlinux_kernel
3.13 ≤
𝑥
< 3.14.41
linuxlinux_kernel
3.15 ≤
𝑥
< 3.16.35
linuxlinux_kernel
3.17 ≤
𝑥
< 3.18.14
linuxlinux_kernel
3.19 ≤
𝑥
< 3.19.7
linuxlinux_kernel
4.0 ≤
𝑥
< 4.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.106-3
fixed
bookworm (security)
6.1.112-1
fixed
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.226-1
fixed
sid
6.11.6-1
fixed
trixie
6.11.5-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
artful
not-affected
bionic
not-affected
trusty
Fixed 3.13.0-57.95
released
xenial
not-affected
zesty
not-affected
linux-armadaxp
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-aws
artful
dne
bionic
not-affected
trusty
not-affected
xenial
not-affected
zesty
dne
linux-azure
artful
dne
bionic
not-affected
trusty
not-affected
xenial
not-affected
zesty
dne
linux-euclid
artful
dne
bionic
dne
trusty
dne
xenial
not-affected
zesty
dne
linux-flo
artful
dne
bionic
dne
trusty
dne
xenial
ignored
zesty
dne
linux-gcp
artful
dne
bionic
not-affected
trusty
dne
xenial
not-affected
zesty
dne
linux-gke
artful
dne
bionic
dne
trusty
dne
xenial
not-affected
zesty
dne
linux-goldfish
artful
dne
bionic
dne
trusty
dne
xenial
ignored
zesty
ignored
linux-grouper
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-hwe
artful
dne
bionic
not-affected
trusty
dne
xenial
not-affected
zesty
dne
linux-hwe-edge
artful
dne
bionic
Fixed 4.18.0-8.9~18.04.1
released
trusty
dne
xenial
not-affected
zesty
dne
linux-kvm
artful
dne
bionic
not-affected
trusty
dne
xenial
not-affected
zesty
dne
linux-linaro-omap
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-linaro-shared
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-linaro-vexpress
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-lts-quantal
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-lts-raring
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-lts-saucy
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-lts-trusty
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-lts-utopic
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-lts-vivid
artful
dne
bionic
dne
trusty
ignored
xenial
dne
zesty
dne
linux-lts-wily
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-lts-xenial
artful
dne
bionic
dne
trusty
not-affected
xenial
dne
zesty
dne
linux-maguro
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-mako
artful
dne
bionic
dne
trusty
dne
xenial
ignored
zesty
dne
linux-manta
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-oem
artful
dne
bionic
not-affected
trusty
dne
xenial
not-affected
zesty
dne
linux-qcm-msm
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne
linux-raspi2
artful
not-affected
bionic
not-affected
trusty
dne
xenial
not-affected
zesty
not-affected
linux-snapdragon
artful
not-affected
bionic
not-affected
trusty
dne
xenial
not-affected
zesty
not-affected
linux-ti-omap4
artful
dne
bionic
dne
trusty
dne
xenial
dne
zesty
dne