cbcvebase.
CVE-2017-7482
published 2018-07-30

CVE-2017-7482: In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.47%
37.5th percentile
In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.11.11-1 (bookworm)linux 4.11.11-1 (bookworm)
linuxlinux_kernel< 3.2.903.2.90
linuxlinux_kernel>= 0 < 4.11.11-14.11.11-1
linuxlinux_kernel>= 0 < 4.11.11-14.11.11-1
linuxlinux_kernel>= 0 < 4.11.11-14.11.11-1
linuxlinux_kernel>= 0 < 4.11.11-14.11.11-1
linuxlinux_kernel>= 0 < 3.13.0-126.1753.13.0-126.175
linuxlinux_kernel>= 0 < 4.4.0-92.1154.4.0-92.115
linuxlinux_kernel>= 0 < 4.4.0-89.1124.4.0-89.112
linuxlinux_kernel>= 3.11 < 3.16.453.16.45
linuxlinux_kernel>= 3.17 < 3.18.593.18.59
linuxlinux_kernel>= 3.19 < 4.1.434.1.43
linuxlinux_kernel>= 3.3 < 3.10.1083.10.108
linuxlinux_kernel>= 4.10 < 4.11.84.11.8
linuxlinux_kernel>= 4.2 < 4.4.754.4.75
linuxlinux_kernel>= 4.5 < 4.9.354.9.35
redhatenterprise_mrg

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.