CVE-2017-10663 describes a privilege escalation vulnerability in the Linux kernel's F2FS filesystem, specifically within the sanity_check_ckpt function. This flaw, present in versions prior to 4.12.4, allows local users to gain elevated privileges due to improper validation of blkoff and segno arrays. With a CVSS score of 7.8 (High), it represents a significant risk, as an attacker can achieve high confidentiality, integrity, and availability impact with low attack complexity and no user interaction. While the vulnerability is severe, there is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.8, < 3.18.64CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.1.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.2, < 4.4.81CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.42CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.12.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.