CVE-2017-11176
HIGH 7.8EPSS 3.6%
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 3.63% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2017-07-11
- Updated
- 2024-08-05
Proof-of-concept exploits (11)
- DoubleMice/cve-2017-111760★ · 2018-11-22
- Gobinath-B/Exploit-Developement1★ · 2022-05-29
- Lexterl33t/Exploit-Kernel0★ · 2021-07-29
- Sama-Ayman-Mokhtar/CVE-2017-111760★ · 2022-07-16
- Yanoro/CVE-2017-111760★ · 2024-02-17
- c3r34lk1ll3r/CVE-2017-111761★ · 2020-04-10
- jopraveen/exploit-development72★ · 2025-01-16
- leonardo1101/cve-2017-111760★ · 2019-12-23
- lexfo/cve-2017-1117626★ · 2018-10-02
- pjlantz/optee-qemu76★ · 2021-12-28
- prince-stark/Exploit-Developement1★ · 2022-05-29