CVE-2017-1000364
Last modified
CVE-2017-1000364 is a vulnerability of currently unknown severity. An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).. EPSS estimates a 5.19% chance of exploitation in the next 30 days.
Description
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.11.5 |
References
- http://www.securityfocus.com/bid/99130Issue Tracking, VDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000364Third Party Advisory, VDB Entry
- https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txtThird Party Advisory
- https://www.suse.com/security/cve/CVE-2017-1000364/Third Party Advisory
- https://www.suse.com/support/kb/doc/?id=7020973Third Party Advisory
- http://www.securityfocus.com/bid/99130Issue Tracking, VDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000364Third Party Advisory, VDB Entry
- https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txtThird Party Advisory
- https://www.suse.com/security/cve/CVE-2017-1000364/Third Party Advisory
- https://www.suse.com/support/kb/doc/?id=7020973Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1000364?
How severe is CVE-2017-1000364?
How do I fix CVE-2017-1000364?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-1000358Controller throws an exception and does not allow user to ad…
- CVE-2017-1000359Java out of memory error and significant increase in resourc…
- CVE-2017-1000360StreamCorruptedException and NullPointerException in OpenDay…
- CVE-2017-1000361DOMRpcImplementationNotAvailableException when sending Port-…
- CVE-2017-1000362The re-key admin monitor was introduced in Jenkins 1.498 and…
- CVE-2017-1000363Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missin…7.8
- CVE-2017-1000365The Linux Kernel imposes a size restriction on the arguments…7.8
- CVE-2017-1000366glibc contains a vulnerability that allows specially crafted…
- CVE-2017-1000367Todd Miller's sudo version 1.8.20 and earlier is vulnerable …
- CVE-2017-1000368Todd Miller's sudo version 1.8.20p1 and earlier is vulnerabl…
- CVE-2017-1000369Exim supports the use of multiple "-p" command line argument…4
- CVE-2017-1000370The offset2lib patch as used in the Linux Kernel contains a …7.8
Are you affected by CVE-2017-1000364?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
