Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-7308

55
FAUCET Score

CVE-2017-7308 is a critical vulnerability in the Linux kernel (through 4.10.6) affecting the packet_set_ring function, specifically an integer signedness error leading to an out-of-bounds write. This flaw allows a local attacker to cause a denial of service or, with CAP_NET_RAW capabilities, achieve privilege escalation. With a CVSS score of 7.8 (High) and an EPSS score of 0.832, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. Multiple public exploits exist, including Metasploit modules and several ExploitDB entries, demonstrating its exploitability for privilege escalation. Although not listed on the KEV catalog, its high FAUCET Risk Score of 99/100, significant community discussion, and media coverage indicate considerable attention and potential for active exploitation. Organizations should prioritize patching affected Linux kernel versions to mitigate this threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.27, < 3.2.89CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.3, < 3.10.107CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.12.74CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.16.44CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.17, < 3.18.52CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
17.83%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: AF_PACKET packet_set_ring Privilege Escalation · Mar 29, 2017
ExploitDB: EDB-47168 · Dec 29, 2018
This CVE's current EPSS score of 0.1783 is in the 99th percentile among its peer group of 16,985 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-754.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-514.21.1.rt56.438.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-514.21.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-514.rt56.221.el6rt
View patch

Vendor Advisories (1)

redhatCVE-2017-7308Important

kernel: net/packet: overflow in check for priv area size

Mar 29, 2017

References

access.redhat.com / errata/RHSA-2017:1297
Third Party Advisory
access.redhat.com / errata/RHSA-2017:1298
Third Party Advisory
access.redhat.com / errata/RHSA-2017:1308
Third Party Advisory
access.redhat.com / errata/RHSA-2018:1854
Third Party Advisory
googleprojectzero.blogspot.com / 2017/05/exploiting-linux-kernel-via-packet.html
Third Party Advisory
patchwork.ozlabs.org / patch/744811
Third Party Advisory
patchwork.ozlabs.org / patch/744812
Third Party Advisory
patchwork.ozlabs.org / patch/744813
Third Party Advisory
source.android.com / security/bulletin/2017-07-01
Third Party Advisory
exploit-db.com / exploits/41994
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/44654
Third Party AdvisoryVDB Entry
securityfocus.com / bid/97234
Third Party AdvisoryVDB Entry