CVE-2017-14140 is a medium-severity vulnerability affecting the Linux kernel before version 4.12.9, specifically within the move_pages system call. A local attacker can exploit this flaw to bypass Address Space Layout Randomization (ASLR) and determine the memory layout of setuid executables. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability could lead to information disclosure (CWE-200) that aids in further attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.12.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.