CVE-2017-18017
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 3, 2018
Updated: Jan 3, 2025
CWE ID 416
Summary
CVE-2017-18017 is a vulnerability affecting the Linux kernel version before 4.11 and 4.9.x before 4.9.36. The issue lies within the tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c. Malicious actors can exploit this vulnerability to cause a denial of service via use-after-free and memory corruption attacks. Additionally, there is a possibility of unspecified other impacts. This vulnerability can be leveraged if xt_TCPMSS is present in an iptables action, making it a significant security concern for affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.