Sploitus

CVE-2017-11176

15 known exploits for CVE-2017-11176

The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.

Linux Linux Kernel
< 3.2.92, 3.16.47, 3.18.61, 4.1.43, 4.4.77, 4.9.38, 4.11.11, 4.12.2
CVSS 3.1
7.8 HIGH
EPSS
3.6% (89th percentile)
Weakness
CWE-416
NVD status
Modified
Published
2017-07-11
CVE-2017-11176 at NVD
Authoritative description, scoring and affected products

15 known exploits for CVE-2017-11176

Proof-of-concept code and exploit modules indexed by Sploitus