15 Linux Kernel CVEs in October 2017
Full month · Source: NIST NVD
In October 2017, 15 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 7 were rated High severity and 8 Medium. CVE-2017-1000253 was confirmed as actively exploited in the wild and added to the CISA Known Exploited Vulnerabilities catalog. October's 15 CVEs represent 7% of all 2017 Linux kernel CVEs .
Actively Exploited CVEs — October 2017
1 CVE in CISA KEVCVE-2017-1000253 is the only Linux kernel CVE from October 2017 confirmed as actively exploited in the wild. It carries a CVSS score of 7.8 (High severity) and is listed in the CISA Known Exploited Vulnerabilities catalog.
| CVE ID | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|
| CVE-2017-1000253 | High KEV | 7.8 | 2017-10-05 | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus… |
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2017-15951 | linux | High | 7.8 | 2017-10-28 | The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchronize the actions of updating versus fin… | |
| CVE-2017-15649 | linux | High | 7.8 | 2017-10-19 | net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls… | |
| CVE-2017-12188 | linux | High | 7.8 | 2017-10-11 | arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse g… | |
| CVE-2017-1000253 | linux | High KEV | 7.8 | 2017-10-05 | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb… | |
| CVE-2017-1000111 | linux | High | 7.8 | 2017-10-05 | Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-865… | |
| CVE-2017-15265 | linux | High | 7.0 | 2017-10-16 | Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service … | |
| CVE-2017-1000112 | linux | High | 7.0 | 2017-10-05 | Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE… | |
| CVE-2017-1000255 | linux | Medium | 5.5 | 2017-10-30 | On Linux running on PowerPC hardware (Power8 or later) a user process can craft a signal frame and then do a sigreturn … | |
| CVE-2006-5331 | linux | Medium | 5.5 | 2017-10-29 | The altivec_unavailable_exception function in arch/powerpc/kernel/traps.c in the Linux kernel before 2.6.19 on 64-bit s… | |
| CVE-2017-15537 | linux | Medium | 5.5 | 2017-10-17 | The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feat… | |
| CVE-2017-15299 | linux | Medium | 5.5 | 2017-10-14 | The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is un… | |
| CVE-2017-12192 | linux | Medium | 5.5 | 2017-10-12 | The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.… | |
| CVE-2017-15274 | linux | Medium | 5.5 | 2017-10-12 | security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction wi… | |
| CVE-2017-14991 | linux | Medium | 5.5 | 2017-10-04 | The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive inf… | |
| CVE-2017-14954 | linux | Medium | 5.5 | 2017-10-02 | The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in uninte… |