CVE-2017-1000407Improper Check for Unusual or Exceptional Conditions in Kernel

Severity
7.4HIGHNVD
EPSS
0.5%
top 35.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 14

Description

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 2.8 | Impact: 4.0

Affected Packages6 packages

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 17.10, Enterprise Linux 7.6

Patches

🔴Vulnerability Details

6
GHSA
GHSA-jh8r-93cx-crmc: The Linux Kernel 22022-05-14
OSV
linux-azure vulnerabilities2018-04-24
OSV
linux-hwe, linux-gcp, linux-oem vulnerabilities2018-04-03
OSV
CVE-2017-1000407: The Linux Kernel 22017-12-11
CVEList
CVE-2017-1000407: The Linux Kernel 22017-12-11

📋Vendor Advisories

9
Ubuntu
Linux kernel (Azure) vulnerabilities2018-04-24
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2018-04-05
Ubuntu
Linux kernel vulnerabilities2018-04-04
Ubuntu
Linux kernel vulnerabilities2018-04-03
Ubuntu
Linux (HWE) vulnerabilities2018-04-03

💬Community

2
Bugzilla
CVE-2017-1000407 Kernel: KVM: DoS via write flood to I/O port 0x802017-12-04
Bugzilla
CVE-2017-1000407 Kernel: KVM: DoS via write flood to I/O port 0x80 [fedora-all]2017-12-04
CVE-2017-1000407 — Linux Kernel vulnerability | cvebase