CVE-2017-18202: Use After Free
The oomreaptaskmm function in mm/oomkill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a denial of service (TLB entry leak or use-after-free) or possibly have unspecified other impact by triggering a copytouser call within a certain time window.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18202?
CVE-2017-18202 is classified as a high-severity vulnerability that can lead to denial of service due to improper handling of operations in the Linux kernel.
How do I fix CVE-2017-18202?
To resolve CVE-2017-18202, it is recommended to upgrade to Linux kernel version 4.14.4 or later.
Which Linux kernel versions are affected by CVE-2017-18202?
CVE-2017-18202 affects Linux kernel versions prior to 4.14.4 as well as certain versions between 4.6 and 4.9.68.
What types of attacks can CVE-2017-18202 facilitate?
CVE-2017-18202 can allow attackers to execute denial of service attacks or potentially exploit the system through a use-after-free condition.
Is CVE-2017-18202 present in Red Hat Linux distributions?
Yes, CVE-2017-18202 is present in certain versions of Red Hat Linux prior to the kernel upgrade to 4.14.4.