CVE-2017-7895
The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.81% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- linux/linux kernel · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3886Third Party Advisory
- http://www.securityfocus.com/bid/98085Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1615Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1616Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1647Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1715Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1723Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1798Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2412Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2428Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2429Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2472Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2732Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=13bf9fbff0e5e099e2b6f003a0ab8ae145436309Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/13bf9fbff0e5e099e2b6f003a0ab8ae145436309Patch, Third Party Advisory
- http://www.debian.org/security/2017/dsa-3886Third Party Advisory
- http://www.securityfocus.com/bid/98085Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1615Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1616Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1647Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1715Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1723Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1798Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2412Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2428Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2429Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2472Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2732Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.