VulnerabilityModified
CVE-2017-1000407
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
HIGH 7.4EPSS 1.22%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
- CVSS 3.0
- 7.4 HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-754
- Affected
- redhat/virtualization host · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · linux/linux kernel · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2017/12/04/2Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/102038Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0676Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1062Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1170
- https://access.redhat.com/security/cve/cve-2017-1000407Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3583-1/Third Party Advisory
- https://usn.ubuntu.com/3583-2/Third Party Advisory
- https://usn.ubuntu.com/3617-1/Third Party Advisory
- https://usn.ubuntu.com/3617-2/Third Party Advisory
- https://usn.ubuntu.com/3619-1/Third Party Advisory
- https://usn.ubuntu.com/3619-2/Third Party Advisory
- https://usn.ubuntu.com/3632-1/Third Party Advisory
- https://www.debian.org/security/2017/dsa-4073Third Party Advisory
- https://www.debian.org/security/2018/dsa-4082Third Party Advisory
- https://www.spinics.net/lists/kvm/msg159809.htmlPatch
- http://www.openwall.com/lists/oss-security/2017/12/04/2Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/102038Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0676Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1062Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1170
- https://access.redhat.com/security/cve/cve-2017-1000407Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3583-1/Third Party Advisory
- https://usn.ubuntu.com/3583-2/Third Party Advisory
- https://usn.ubuntu.com/3617-1/Third Party Advisory
- https://usn.ubuntu.com/3617-2/Third Party Advisory
- https://usn.ubuntu.com/3619-1/Third Party Advisory
- https://usn.ubuntu.com/3619-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.