Linux Kernel CVE Statistics
17 Linux Kernel CVEs in May 2017
Full month · Source: NIST NVD
In May 2017, 17 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 8 were rated High severity and 9 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. May's 17 CVEs represent 8% of all 2017 Linux kernel CVEs , down from April's 27 (a 37% month-over-month decrease) .
17
Total CVEs
0
Critical
8
High
9
Medium
0
Low
0
KEV Exploited
All CVEs — May 2017
17 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2017-9074 | linux | High | 7.8 | 2017-05-19 | The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may b… | |
| CVE-2017-9075 | linux | High | 7.8 | 2017-05-19 | The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whi… | |
| CVE-2017-9077 | linux | High | 7.8 | 2017-05-19 | The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whi… | |
| CVE-2017-9076 | linux | High | 7.8 | 2017-05-19 | The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, wh… | |
| CVE-2017-7487 | linux | High | 7.8 | 2017-05-14 | The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which all… | |
| CVE-2017-8890 | linux | High | 7.8 | 2017-05-10 | The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attacker… | |
| CVE-2015-9004 | linux | High | 7.8 | 2017-05-02 | kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain priv… | |
| CVE-2014-9940 | linux | High | 7.0 | 2017-05-02 | The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to … | |
| CVE-2017-8831 | linux | Medium | 6.4 | 2017-05-08 | The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local… | |
| CVE-2017-9242 | linux | Medium | 5.5 | 2017-05-27 | The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whet… | |
| CVE-2017-9211 | linux | Medium | 5.5 | 2017-05-23 | The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey functi… | |
| CVE-2017-9150 | linux | Medium | 5.5 | 2017-05-22 | The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks valu… | |
| CVE-2017-9059 | linux | Medium | 5.5 | 2017-05-18 | The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource c… | |
| CVE-2017-7495 | linux | Medium | 5.5 | 2017-05-15 | fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-befo… | |
| CVE-2017-8925 | linux | Medium | 5.5 | 2017-05-12 | The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause… |