Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-15129

19
FAUCET Score

CVE-2017-15129 is a use-after-free vulnerability in the Linux kernel (before 4.14.11) affecting network namespaces, specifically in the get_net_ns_by_id() function. This flaw, categorized as CWE-362, impacts various distributions including Canonical, Fedora, and Red Hat. With a CVSS score of 4.7 (Medium), it requires local access with high attack complexity and low privileges, primarily leading to a denial of service through kernel memory corruption, though privilege escalation is not entirely ruled out. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0, < 4.14.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:4.15:rc1:*:*:*:*:*:*
4.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:4.15:rc2:*:*:*:*:*:*
4.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:4.15:rc3:*:*:*:*:*:*
4.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:4.15:rc4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 77th percentile among its peer group of 1,296 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-862.rt56.804.el7
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-862.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Extended Update SupportFixed in: kernel-0:3.10.0-693.55.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-49.el7a
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: realtime-kernel

Vendor Advisories (1)

redhatCVE-2017-15129Moderate

kernel: net: double-free and memory corruption in get_net_ns_by_id()

Dec 19, 2017

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Patch
access.redhat.com / errata/RHSA-2018:0654
Third Party Advisory
access.redhat.com / errata/RHSA-2018:0676
Third Party Advisory
access.redhat.com / errata/RHSA-2018:1062
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1946
Third Party Advisory
access.redhat.com / security/cve/CVE-2017-15129
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
seclists.org / oss-sec/2018/q1/7
Mailing ListThird Party Advisory
github.com / torvalds/linux/commit/21b5944350052d2583e82dd59b19a9ba94a007f0
Patch
marc.info
Mailing ListPatchThird Party Advisory
marc.info
Mailing ListThird Party Advisory
usn.ubuntu.com / 3617-1
Third Party Advisory
usn.ubuntu.com / 3617-2
Third Party Advisory
usn.ubuntu.com / 3617-3
Third Party Advisory
usn.ubuntu.com / 3619-1
Third Party Advisory
usn.ubuntu.com / 3619-2
Third Party Advisory
usn.ubuntu.com / 3632-1
Third Party Advisory
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.14.11
Release Notes
securityfocus.com / bid/102485
Broken Link