kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
References
Configurations
History
No history.
Information
Published : 2017-12-27 17:08
Updated : 2025-04-20 01:37
NVD link : CVE-2017-17864
Mitre link : CVE-2017-17864
CVE.ORG link : CVE-2017-17864
JSON object : View
Products Affected
linux
- linux_kernel
debian
- debian_linux
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor