CVE-2017-1000112 is a high-severity memory corruption vulnerability in the Linux kernel, specifically affecting the UDP Fragmentation Offload (UFO) mechanism. It arises when the kernel switches between UFO and non-UFO packet paths during transmission, leading to out-of-bounds writes due to incorrect length calculations. This flaw impacts various versions of the Linux kernel. With a CVSS score of 7.0 (HIGH), this vulnerability has a local attack vector with high attack complexity, but does not require user interaction. Successful exploitation can lead to high impacts on confidentiality, integrity, and availability, potentially allowing for privilege escalation. Exploit intelligence indicates that Metasploit modules are available for this vulnerability, demonstrating its exploitability. While it is not listed on the KEV catalog, its high EPSS score suggests a significant likelihood of exploitation. Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.15, < 3.10.108CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.16.47CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.65CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.4.82CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.43CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.