CVE-2017-11473

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.

References

http://www.securityfocus.com/bid/100010

https://access.redhat.com/errata/RHSA-2018:0654

https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=70ac67826602edf8c0ccb413e5ba7eacf597a60c

https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=96301209473afd3f2f274b91cb7082d161b9be65

https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=dad5ab0db8deac535d03e3fe3d8f2892173fa6a4

https://source.android.com/security/bulletin/pixel/2018-01-01

https://usn.ubuntu.com/3754-1/

Details

Source: MITRE

Published: 2017-07-20

Updated: 2021-01-05

Type: CWE-120

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Tenable Plugins

View all (25 total)

IDNameProductFamilySeverity
124976EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1523)NessusHuawei Local Security Checks
critical
124821EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1498)NessusHuawei Local Security Checks
high
121722Photon OS 1.0: Linux PHSA-2017-0028NessusPhotonOS Local Security Checks
high
112113Ubuntu 14.04 LTS : Linux kernel vulnerabilities (USN-3754-1)NessusUbuntu Local Security Checks
critical
111877Photon OS 1.0: Linux PHSA-2017-0028 (deprecated)NessusPhotonOS Local Security Checks
high
108942RHEL 7 : kernel-alt (RHSA-2018:0654)NessusRed Hat Local Security Checks
high
106469OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0015) (BlueBorne) (Meltdown) (Spectre) (Stack Clash)NessusOracleVM Local Security Checks
critical
105248OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0174) (BlueBorne) (Dirty COW) (Stack Clash)NessusOracleVM Local Security Checks
high
105247Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3659)NessusOracle Linux Local Security Checks
high
105147OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0173) (BlueBorne) (Stack Clash)NessusOracleVM Local Security Checks
high
105145Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3658)NessusOracle Linux Local Security Checks
high
105144Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3657)NessusOracle Linux Local Security Checks
high
104454OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0168)NessusOracleVM Local Security Checks
high
104371Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2017-3637)NessusOracle Linux Local Security Checks
high
104370Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3636)NessusOracle Linux Local Security Checks
high
104253SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:2869-1) (KRACK)NessusSuSE Local Security Checks
high
103354SUSE SLES11 Security Update : kernel (SUSE-SU-2017:2525-1) (Stack Clash)NessusSuSE Local Security Checks
critical
103110SUSE SLES11 Security Update : kernel (SUSE-SU-2017:2389-1) (Stack Clash)NessusSuSE Local Security Checks
high
102997EulerOS 2.0 SP1 : kernel (EulerOS-SA-2017-1159)NessusHuawei Local Security Checks
critical
102838SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:2286-1)NessusSuSE Local Security Checks
high
102544Amazon Linux AMI : kernel (ALAS-2017-870)NessusAmazon Linux Local Security Checks
high
102333openSUSE Security Update : the Linux Kernel (openSUSE-2017-891)NessusSuSE Local Security Checks
high
102332openSUSE Security Update : the Linux Kernel (openSUSE-2017-890)NessusSuSE Local Security Checks
high
101994Fedora 24 : kernel (2017-544eef948f)NessusFedora Local Security Checks
high
101992Fedora 25 : kernel (2017-39b5facda0)NessusFedora Local Security Checks
high