CVE-2017-13694

CVSS 3.0 Score 5.5 of 10 (medium)

Details

Published Aug 25, 2017
Updated: Dec 18, 2024
CWE ID 200

Summary

CVE-2017-13694 is a vulnerability affecting the Linux kernel up to version 4.12.9. In the acpica/psobject.c file, the acpi_ps_complete_final_op() function fails to flush the node and node_ext caches. This oversight results in a kernel stack dump, granting local users access to sensitive information from kernel memory. Moreover, this vulnerability undermines the KASLR (Kernel Address Space Layout Randomization) protection mechanism in older versions of the kernel (up to 4.9), enabling attackers to bypass it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share