CVE-2017-11472
The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
- CVSS 3.0
- 7.1 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-755
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3b2d69114fefa474fca542e51119036dceb4aa6fIssue Tracking, Patch, Third Party Advisory
- https://github.com/acpica/acpica/commit/a23325b2e583556eae88ed3f764e457786bf4df6Issue Tracking, Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/3b2d69114fefa474fca542e51119036dceb4aa6fIssue Tracking, Patch, Third Party Advisory
- https://usn.ubuntu.com/3619-1/
- https://usn.ubuntu.com/3619-2/
- https://usn.ubuntu.com/3754-1/
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3b2d69114fefa474fca542e51119036dceb4aa6fIssue Tracking, Patch, Third Party Advisory
- https://github.com/acpica/acpica/commit/a23325b2e583556eae88ed3f764e457786bf4df6Issue Tracking, Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/3b2d69114fefa474fca542e51119036dceb4aa6fIssue Tracking, Patch, Third Party Advisory
- https://usn.ubuntu.com/3619-1/
- https://usn.ubuntu.com/3619-2/
- https://usn.ubuntu.com/3754-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.