CVE-2017-7308 is a critical vulnerability in the Linux kernel (through 4.10.6) affecting the packet_set_ring function, specifically an integer signedness error leading to an out-of-bounds write. This flaw allows a local attacker to cause a denial of service or, with CAP_NET_RAW capabilities, achieve privilege escalation. With a CVSS score of 7.8 (High) and an EPSS score of 0.832, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. Multiple public exploits exist, including Metasploit modules and several ExploitDB entries, demonstrating its exploitability for privilege escalation. Although not listed on the KEV catalog, its high FAUCET Risk Score of 99/100, significant community discussion, and media coverage indicate considerable attention and potential for active exploitation. Organizations should prioritize patching affected Linux kernel versions to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.27, < 3.2.89CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.10.107CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.74CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.13, < 3.16.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.52CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.