CVE-2017-14954
The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call.
- Affected products
- Alt Linux, Linux Kernel, Ubuntu
- Linux Linux Kernel
- ≤ 4.13.4
- CVSS 3.0
- 5.5 MEDIUM
- EPSS
- 1.0% (60th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2017-10-01
CVE-2017-14954 at NVD
1 known exploit for CVE-2017-14954
Proof-of-concept code and exploit modules indexed by Sploitus