CVE-2017-14489 is a denial-of-service vulnerability affecting the Linux kernel through version 4.13.2, specifically within the iscsi_if_rx function due to incorrect length validation. With a CVSS score of 5.5 (Medium), this vulnerability can be exploited locally with low attack complexity, allowing an authenticated local user to cause a system panic. While not actively exploited in the wild and not on the KEV catalog, a public proof-of-concept exploit (EDB-42932) exists, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.13.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.