CVE-2017-10662 is a privilege escalation vulnerability in the Linux kernel, specifically affecting versions prior to 4.11.1. It stems from a lack of validation in the segment count within the fs/f2fs/super.c file, allowing local users to gain elevated privileges. With a CVSS score of 7.8 (High), this vulnerability is easily exploitable locally with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed on the KEV catalog, and community discussion and media coverage are minimal, suggesting it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.18.53CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.1.41CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.2, < 4.4.68CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.28CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.10.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.