CVE-2017-1000364
Last modified
CVE-2017-1000364 is a vulnerability of currently unknown severity. An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).. EPSS estimates a 5.19% chance of exploitation in the next 30 days.
Description
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.11.5 |
References
- http://www.securityfocus.com/bid/99130Issue Tracking, VDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000364Third Party Advisory, VDB Entry
- https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txtThird Party Advisory
- https://www.suse.com/security/cve/CVE-2017-1000364/Third Party Advisory
- https://www.suse.com/support/kb/doc/?id=7020973Third Party Advisory
- http://www.securityfocus.com/bid/99130Issue Tracking, VDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000364Third Party Advisory, VDB Entry
- https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txtThird Party Advisory
- https://www.suse.com/security/cve/CVE-2017-1000364/Third Party Advisory
- https://www.suse.com/support/kb/doc/?id=7020973Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1000364?
How severe is CVE-2017-1000364?
How do I fix CVE-2017-1000364?
Are you affected by CVE-2017-1000364?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
