Linux Kernel CVE Statistics

15 Linux Kernel CVEs in October 2017

Full month · Source: NIST NVD

September 2017 November 2017

In October 2017, 15 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 7 were rated High severity and 8 Medium. CVE-2017-1000253 was confirmed as actively exploited in the wild and added to the CISA Known Exploited Vulnerabilities catalog. October's 15 CVEs represent 7% of all 2017 Linux kernel CVEs .

15
Total CVEs
0
Critical
7
High
8
Medium
0
Low
1
KEV Exploited

Actively Exploited CVEs — October 2017

1 CVE in CISA KEV

CVE-2017-1000253 is the only Linux kernel CVE from October 2017 confirmed as actively exploited in the wild. It carries a CVSS score of 7.8 (High severity) and is listed in the CISA Known Exploited Vulnerabilities catalog.

CVE ID Severity CVSS Published Description
CVE-2017-1000253 High KEV 7.8 2017-10-05 Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus…
KEV data sourced from CISA Known Exploited Vulnerabilities catalog.
All CVEs — October 2017 15 CVEs
All (15) Critical (0) High (7) Medium (8) Low (0)
CVE ID Package Severity CVSS Published Description
CVE-2017-15951 linux High 7.8 2017-10-28 The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchronize the actions of updating versus fin…
CVE-2017-15649 linux High 7.8 2017-10-19 net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls…
CVE-2017-12188 linux High 7.8 2017-10-11 arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse g…
CVE-2017-1000253 linux High KEV 7.8 2017-10-05 Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb…
CVE-2017-1000111 linux High 7.8 2017-10-05 Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-865…
CVE-2017-15265 linux High 7.0 2017-10-16 Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service …
CVE-2017-1000112 linux High 7.0 2017-10-05 Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE…
CVE-2017-1000255 linux Medium 5.5 2017-10-30 On Linux running on PowerPC hardware (Power8 or later) a user process can craft a signal frame and then do a sigreturn …
CVE-2006-5331 linux Medium 5.5 2017-10-29 The altivec_unavailable_exception function in arch/powerpc/kernel/traps.c in the Linux kernel before 2.6.19 on 64-bit s…
CVE-2017-15537 linux Medium 5.5 2017-10-17 The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feat…
CVE-2017-15299 linux Medium 5.5 2017-10-14 The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is un…
CVE-2017-12192 linux Medium 5.5 2017-10-12 The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.…
CVE-2017-15274 linux Medium 5.5 2017-10-12 security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction wi…
CVE-2017-14991 linux Medium 5.5 2017-10-04 The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive inf…
CVE-2017-14954 linux Medium 5.5 2017-10-02 The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in uninte…

Frequently Asked Questions

How many Linux kernel CVEs were published in October 2017?

15 Linux kernel CVEs were published in October 2017, sourced from the NIST National Vulnerability Database. Of these, 0 were rated Critical severity, 7 High, and 8 Medium.

Which Linux kernel CVEs from October 2017 are actively exploited?

1 Linux kernel CVE from October 2017 is listed in the CISA Known Exploited Vulnerabilities catalog: CVE-2017-1000253 (CVSS 7.8) . This indicates confirmed active exploitation in the wild. View all actively exploited 2017 CVEs →

How does October 2017 compare to other months?

October 2017's 15 CVEs represent 7% of all 2017 Linux kernel CVEs. View the full 2017 breakdown →

September 2017 2017 statistics November 2017