CVE-2017-16994
MEDIUM 5.5EPSS 2.1%
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.
- CVSS v3.0
- 5.5 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 2.08% chance of exploitation in the next 30 days, 80th percentile
- Published
- 2017-11-27
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- jedai47/CVE-2017-169940★ · 2024-05-22
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/43178
- https://www.exploit-db.com/exploits/44304
- https://www.exploit-db.com/exploits/44303