CVE-2017-18344
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID/timers is read). This allows userspace applications to read arbitrary kernel memory (on a kernel built with CONFIG_POSIX_TIMERS and CONFIG_CHECKPOINT_RESTORE).
- Linux Linux Kernel
- < 4.14.8
- Fix
- Available
- CVSS 3.0
- 5.5 MEDIUM
- EPSS
- 3.3% (88th percentile)
- Weakness
- CWE-125
- NVD status
- Modified
- Published
- 2018-07-26
CVE-2017-18344 at NVD
10 known exploits for CVE-2017-18344
Proof-of-concept code and exploit modules indexed by Sploitus
kernel-exploits
docker_escape_pwn
exploit_linux_kernel4.13
Exploit for CVE-2016-2384
Linux Kernel 4.14.7 ( Ubuntu 16.04 / CentOS 7) Arbitrary File Read Exploit
Linux Kernel 4.14.7 (Ubuntu 16.04 CentOS 7) - (KASLR SMEP Bypass) Arbitrary File Read
Linux Kernel 4.14.7 (Ubuntu 16.04 / CentOS 7) - (KASLR & SMEP Bypass) Arbitrary File Read
Linux Kernel 4.14.7 (Ubuntu 16.04 / CentOS 7) Arbitrary File Read
Immunity Canvas: SHOW_TIMER_LEAK
Exploit for CVE-2016-2384