CVE-2017-16995
HIGH 7.8EPSS 30.1%
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 30.05% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2017-12-22
- Updated
- 2024-08-05
Proof-of-concept exploits (24)
- Al1ex/CVE-2017-1699513★ · 2021-09-08
- C0dak/CVE-2017-169950★ · 2018-03-19
- Dk0n9/linux_exploit2★ · 2018-03-16
- Khalidhaimur/privilege-escalation0★ · 2025-02-09
- LucidOfficial/Linux-exploit-suggestor0★ · 2022-06-19
- Lumindu/CVE-2017-16995-Linux-Kernel---BPF-Sign-Extension-Local-Privilege-Escalation-0★ · 2020-05-12
- Villaquiranm/security_information_systems0★ · 2018-12-02
- ZhiQiAnSecFork/cve-2017-169950★ · 2023-12-15
- anldori/CVE-2017-169950★ · 2023-01-09
- catuhub/dockerized-vms15★ · 2021-01-14
- dangokyo/CVE_2017_169956★ · 2018-05-24
- fei9747/CVE-2017-169950★ · 2022-11-29
- gugronnier/CVE-2017-169951★ · 2018-12-05
- ivilpez/cve-2017-16995.c0★ · 2022-11-26
- littlebin404/CVE-2017-169951★ · 2019-08-14
- mareks1007/cve-2017-169950★ · 2023-12-13
- ph4ntonn/CVE-2017-169952★ · 2021-01-28
- pradeepavula/Linux-Exploits-LES-0★ · 2024-02-25
- senyuuri/cve-2017-169951★ · 2019-01-22
- thelostvoice/global-takeover2★ · 2021-10-13
- thelostvoice/inept-us-military1★ · 2021-10-12
- vnik5287/CVE-2017-169951★ · 2019-07-23
- xxxTectationxxx/CVE-2017-169950★ · 2025-08-12
- WhatsWrongAndWhy/CVE-2017-16995
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/45058
- https://www.exploit-db.com/exploits/45010
- https://www.exploit-db.com/exploits/44298