SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-18017

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other…

CRITICAL 9.8EPSS 52.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 52.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
52.84% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-416
Affected
linux/linux kernel · debian/debian linux · arista/eos · f5/arx · suse/caas platform · suse/linux enterprise debuginfo · suse/linux enterprise module for public cloud · suse/linux enterprise point of sale · suse/openstack cloud · opensuse/leap · suse/linux enterprise desktop · suse/linux enterprise high availability · suse/linux enterprise high availability extension · suse/linux enterprise live patching · suse/linux enterprise real time extension · suse/linux enterprise server · suse/linux enterprise software development kit · suse/linux enterprise workstation extension · openstack/cloud magnum orchestration · canonical/ubuntu linux · +9 more
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.