CVE-2017-14991: Infoleak
Published Oct 3, 2017
·Updated
Last updated 29 November 2024
Other sources
The sgioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SGGETREQUESTTABLE ioctl call for /dev/sg0.
Affected Software
2 affected componentsFixes available
Linux Linux kernel<=4.13.3
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
Remediation
Event History
Oct 3, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:30 PM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·01:57 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2017-14991?
CVE-2017-14991 is a vulnerability in the Linux kernel that allows local users to obtain sensitive information from uninitialized kernel heap-memory locations.
2
How does CVE-2017-14991 affect Linux?
CVE-2017-14991 affects the Linux kernel before version 4.13.4.
3
What is the severity of CVE-2017-14991?
The severity of CVE-2017-14991 is high.
4
How can I fix CVE-2017-14991?
To fix CVE-2017-14991, update your Linux kernel to version 4.13.4 or later.
5
Where can I find more information about CVE-2017-14991?
You can find more information about CVE-2017-14991 on the Linux kernel website and the referenced links.