Linux Kernel CVE Statistics
26 Linux Kernel CVEs in December 2017
Full month · Source: NIST NVD
In December 2017, 26 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 18 were rated High severity and 6 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. December's 26 CVEs represent 12% of all 2017 Linux kernel CVEs , down from November's 34 (a 24% month-over-month decrease) .
26
Total CVEs
0
Critical
18
High
6
Medium
2
Low
0
KEV Exploited
All CVEs — December 2017
26 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2017-16996 | linux | High | 7.8 | 2017-12-27 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrup… | |
| CVE-2017-16995 | linux | High | 7.8 | 2017-12-27 | The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial… | |
| CVE-2017-17856 | linux | High | 7.8 | 2017-12-27 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrup… | |
| CVE-2017-17855 | linux | High | 7.8 | 2017-12-27 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrup… | |
| CVE-2017-17853 | linux | High | 7.8 | 2017-12-27 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrup… | |
| CVE-2017-17863 | linux | High | 7.8 | 2017-12-27 | kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values a… | |
| CVE-2017-17854 | linux | High | 7.8 | 2017-12-27 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overf… | |
| CVE-2017-17852 | linux | High | 7.8 | 2017-12-27 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrup… | |
| CVE-2017-17857 | linux | High | 7.8 | 2017-12-27 | The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cau… | |
| CVE-2017-17806 | linux | High | 7.8 | 2017-12-20 | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptog… | |
| CVE-2017-17805 | linux | High | 7.8 | 2017-12-20 | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowi… | |
| CVE-2017-17448 | linux | High | 7.8 | 2017-12-07 | net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for… | |
| CVE-2017-17450 | linux | High | 7.8 | 2017-12-07 | net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callbac… | |
| CVE-2017-8824 | linux | High | 7.8 | 2017-12-05 | The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileg… | |
| CVE-2017-15868 | linux | High | 7.8 | 2017-12-05 | The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l… |