Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-12190

20
FAUCET Score

CVE-2017-12190 describes a memory leak vulnerability in the Linux kernel, specifically affecting versions prior to 4.13.8. This flaw, residing in the bio_map_user_iov and bio_unmap_user functions within block/bio.c, results from unbalanced reference counting when handling SCSI I/O vectors with small, consecutive buffers. The vulnerability is rated Medium severity (CVSS 6.5) due to its potential for a system lockup caused by an out-of-memory condition, exploitable by a guest OS user against the host if a SCSI disk is passed through. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.13.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.5MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.0
Impact Score
4.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 93rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.47.2.rt56.641.el6rt
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-754.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-862.rt56.804.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-49.el7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-862.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Extended Update SupportFixed in: kernel-0:3.10.0-693.47.2.el7
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2017-12190Moderate

kernel: memory leak when merging buffers in SCSI IO vectors

Sep 21, 2017

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Issue TrackingPatchVendor Advisory
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Issue TrackingPatchVendor Advisory
access.redhat.com / errata/RHSA-2018:0654
access.redhat.com / errata/RHSA-2018:0676
access.redhat.com / errata/RHSA-2018:1062
access.redhat.com / errata/RHSA-2018:1854
access.redhat.com / errata/RHSA-2019:1170
access.redhat.com / errata/RHSA-2019:1190
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
seclists.org / oss-sec/2017/q4/52
Issue TrackingMailing ListThird Party Advisory
github.com / torvalds/linux/commit/2b04e8f6bbb196cab4b232af0f8d48ff2c7a8058
Issue TrackingPatchThird Party Advisory
github.com / torvalds/linux/commit/95d78c28b5a85bacbc29b8dba7c04babb9b0d467
Issue TrackingPatchThird Party Advisory
lists.debian.org / debian-lts-announce/2017/12/msg00004.html
support.f5.com / csp/article/K93472064
usn.ubuntu.com / 3582-1
usn.ubuntu.com / 3582-2
usn.ubuntu.com / 3583-1
usn.ubuntu.com / 3583-2
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.13.8
Issue TrackingThird Party Advisory
securityfocus.com / bid/101911
Issue TrackingThird Party AdvisoryVDB Entry