CVE-2017-18208: Medium severity Linux Linux kernel vulnerability
Last updated 4 July 2026
Other sources
The madvisewillneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISEWILLNEED for a DAX mapping.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.15 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
Linux kernel (mm/madvise.c)to a version that resolves this vulnerability.Fixed in 4.14.4Patch 6ea8d958a2c95a1d514015d4e29ba21a8c0a1a91
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18208?
CVE-2017-18208 has a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2017-18208?
To fix CVE-2017-18208, update the Linux kernel to version 4.15 or later for Red Hat systems and to specific patched versions for Debian.
Which versions of the Linux kernel are affected by CVE-2017-18208?
CVE-2017-18208 affects Linux kernel versions prior to 4.14.4.
Can CVE-2017-18208 be exploited remotely?
CVE-2017-18208 requires local access for exploitation, making it less likely to be exploited remotely.
What are the implications of CVE-2017-18208 for system stability?
Exploiting CVE-2017-18208 can lead to an infinite loop condition, resulting in a denial of service and potential system instability.