cbcvebase.
CVE-2017-18017
published 2018-01-03

CVE-2017-18017: The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
aristaeos
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.11.6-1 (bookworm)linux 4.11.6-1 (bookworm)
f5arx6.2.0 – 6.4.0
linuxlinux_kernel>= 0 < 4.11.6-14.11.6-1
linuxlinux_kernel>= 0 < 4.11.6-14.11.6-1
linuxlinux_kernel>= 0 < 4.11.6-14.11.6-1
linuxlinux_kernel>= 0 < 4.11.6-14.11.6-1
linuxlinux_kernel>= 0 < 3.13.0-142.1913.13.0-142.191
linuxlinux_kernel>= 3.11 < 3.16.543.16.54
linuxlinux_kernel>= 3.17 < 3.18.603.18.60
linuxlinux_kernel>= 3.19 < 4.1.434.1.43
linuxlinux_kernel>= 3.2 < 3.2.993.2.99
linuxlinux_kernel>= 3.3 < 3.10.1083.10.108
linuxlinux_kernel>= 4.10 < 4.114.11
linuxlinux_kernel>= 4.2 < 4.4.764.4.76
linuxlinux_kernel>= 4.5 < 4.9.364.9.36
openstackcloud_magnum_orchestration
opensuseleap
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL