CVE-2017-5897

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 1.34 % (86th)
1.34% Progress
Affected Products 3
Advisories 13

The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.

Weaknesses
CWE-125
Out-of-bounds Read
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2017-03-23 16:59:00
(7 years ago)
Updated Date
2022-11-03 02:25:13
(22 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 3.7 version and prior 3.10.106 version cpe:2.3:o:linux:linux_kernel >= 3.7 < 3.10.106
  Linux Kernel from 3.11 version and prior 3.12.71 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.12.71
  Linux Kernel from 3.13 version and prior 3.16.41 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.16.41
  Linux Kernel from 3.17 version and prior 3.18.49 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.49
  Linux Kernel from 3.19 version and prior 4.4.50 version cpe:2.3:o:linux:linux_kernel >= 3.19 < 4.4.50
  Linux Kernel from 4.5 version and prior 4.9.11 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.11

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm

Configuration #3

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...