Linux Kernel CVE Statistics
15 Linux Kernel CVEs in September 2017
Full month · Source: NIST NVD
In September 2017, 15 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 4 were rated High severity and 11 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. September's 15 CVEs represent 7% of all 2017 Linux kernel CVEs , up from August's 12 (a 25% month-over-month increase) .
15
Total CVEs
0
Critical
4
High
11
Medium
0
Low
0
KEV Exploited
All CVEs — September 2017
15 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2017-1000251 | linux | High | 8.0 | 2017-09-12 | The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and inclu… | |
| CVE-2017-14497 | linux | High | 7.8 | 2017-09-15 | The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might… | |
| CVE-2017-12154 | linux | High | 7.1 | 2017-09-26 | The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load… | |
| CVE-2017-12146 | linux | High | 7.0 | 2017-09-08 | The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to g… | |
| CVE-2015-5327 | linux | Medium | 6.5 | 2017-09-25 | Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after. | |
| CVE-2017-12168 | linux | Medium | 6.0 | 2017-09-20 | The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM gue… | |
| CVE-2017-1000252 | linux | Medium | 5.5 | 2017-09-26 | The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion fail… | |
| CVE-2015-7837 | linux | Medium | 5.5 | 2017-09-19 | The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secu… | |
| CVE-2017-14340 | linux | Medium | 5.5 | 2017-09-15 | The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesyst… | |
| CVE-2017-14489 | linux | Medium | 5.5 | 2017-09-15 | The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users t… | |
| CVE-2017-14140 | linux | Medium | 5.5 | 2017-09-05 | The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the tar… | |
| CVE-2017-14156 | linux | Medium | 5.5 | 2017-09-05 | The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initializ… | |
| CVE-2017-14106 | linux | Medium | 5.5 | 2017-09-01 | The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of s… | |
| CVE-2015-7553 | linux | Medium | 4.7 | 2017-09-14 | Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_… | |
| CVE-2017-12153 | linux | Medium | 4.4 | 2017-09-21 | A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel t… |