CVE-2017-1000253 is a Linux kernel vulnerability affecting specific long-term kernel versions, particularly those in CentOS and Red Hat Enterprise Linux, that did not backport a critical fix from April 2015. This flaw allows for local privilege escalation due to incorrect memory allocation when loading Position Independent Executables (PIE), leading to a stack-binary overlap. With a CVSS score of 7.8 (High), it presents a significant risk, allowing an attacker with low privileges to achieve full control over the system. This vulnerability is actively exploited, listed in CISA's KEV catalog, and has publicly available exploit code, indicating a high potential for real-world impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:centos:centos:6.0:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:o:centos:centos:6.1:*:*:*:*:*:*:* | ||
6.2CPE matchmatch criteria | cpe:2.3:o:centos:centos:6.2:*:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:centos:centos:6.3:*:*:*:*:*:*:* | ||
6.4CPE matchmatch criteria | cpe:2.3:o:centos:centos:6.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.