Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-1000112

54
FAUCET Score

CVE-2017-1000112 is a high-severity memory corruption vulnerability in the Linux kernel, specifically affecting the UDP Fragmentation Offload (UFO) mechanism. It arises when the kernel switches between UFO and non-UFO packet paths during transmission, leading to out-of-bounds writes due to incorrect length calculations. This flaw impacts various versions of the Linux kernel. With a CVSS score of 7.0 (HIGH), this vulnerability has a local attack vector with high attack complexity, but does not require user interaction. Successful exploitation can lead to high impacts on confidentiality, integrity, and availability, potentially allowing for privilege escalation. Exploit intelligence indicates that Metasploit modules are available for this vulnerability, demonstrating its exploitability. While it is not listed on the KEV catalog, its high EPSS score suggests a significant likelihood of exploitation. Despite this, there is minimal community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.15, < 3.10.108CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.16.47CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.17, < 3.18.65CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.19, < 4.4.82CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.9.43CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
20.80%
Probability of exploitation in next 30 days
EPSS Percentile
97.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Linux Kernel UDP Fragmentation Offset (UFO) Privilege Escalation · Aug 10, 2017
ExploitDB: EDB-47169 · Dec 29, 2018
This CVE's current EPSS score of 0.2080 is in the 100th percentile among its peer group of 1,525 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Long LifeFixed in: kernel-0:2.6.18-348.44.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5 Extended Lifecycle SupportFixed in: kernel-0:2.6.18-438.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-696.16.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-693.5.2.rt56.626.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-693.5.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: kernel-0:3.10.0-514.71.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Telco Extended Update SupportFixed in: kernel-0:3.10.0-514.71.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-514.71.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.5.2.rt56.592.el6rt
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt

Vendor Advisories (1)

redhatCVE-2017-1000112Important

kernel: Exploitable memory corruption due to UFO to non-UFO path switch

Aug 10, 2017

References

access.redhat.com / errata/RHSA-2017:2918
Third Party Advisory
access.redhat.com / errata/RHSA-2017:2930
Third Party Advisory
access.redhat.com / errata/RHSA-2017:2931
Third Party Advisory
access.redhat.com / errata/RHSA-2017:3200
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1931
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1932
Third Party Advisory
access.redhat.com / errata/RHSA-2019:4159
Third Party Advisory
seclists.org / oss-sec/2017/q3/277
Mailing ListPatchThird Party Advisory
github.com / xairy/kernel-exploits/tree/master/CVE-2017-1000112
Third Party Advisory
exploit-db.com / exploits/45147
Third Party AdvisoryVDB Entry
debian.org / security/2017/dsa-3981
Third Party Advisory
securityfocus.com / bid/100262
Third Party AdvisoryVDB Entry
securitytracker.com / id/1039162
Third Party AdvisoryVDB Entry