kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service.
References
Configurations
History
No history.
Information
Published : 2017-12-27 17:08
Updated : 2025-04-20 01:37
NVD link : CVE-2017-17862
Mitre link : CVE-2017-17862
CVE.ORG link : CVE-2017-17862
JSON object : View
Products Affected
linux
- linux_kernel
debian
- debian_linux
CWE
CWE-20
Improper Input Validation