CVE-2017-16994

The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.
References
Link Resource
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=373c4557d2aa362702c4c2d41288fb1e54990b7c Patch
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.2 Release Notes
http://www.securityfocus.com/bid/101969 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:0502
https://bugs.chromium.org/p/project-zero/issues/detail?id=1431 Exploit Issue Tracking Patch
https://github.com/torvalds/linux/commit/373c4557d2aa362702c4c2d41288fb1e54990b7c Patch
https://usn.ubuntu.com/3617-1/
https://usn.ubuntu.com/3617-2/
https://usn.ubuntu.com/3617-3/
https://usn.ubuntu.com/3619-1/
https://usn.ubuntu.com/3619-2/
https://usn.ubuntu.com/3632-1/
https://www.exploit-db.com/exploits/43178/ Exploit Third Party Advisory VDB Entry
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=373c4557d2aa362702c4c2d41288fb1e54990b7c Patch
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.2 Release Notes
http://www.securityfocus.com/bid/101969 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2018:0502
https://bugs.chromium.org/p/project-zero/issues/detail?id=1431 Exploit Issue Tracking Patch
https://github.com/torvalds/linux/commit/373c4557d2aa362702c4c2d41288fb1e54990b7c Patch
https://usn.ubuntu.com/3617-1/
https://usn.ubuntu.com/3617-2/
https://usn.ubuntu.com/3617-3/
https://usn.ubuntu.com/3619-1/
https://usn.ubuntu.com/3619-2/
https://usn.ubuntu.com/3632-1/
https://www.exploit-db.com/exploits/43178/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-11-27 19:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-16994

Mitre link : CVE-2017-16994

CVE.ORG link : CVE-2017-16994


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor