Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-17807

16
FAUCET Score

CVE-2017-17807 is a low-severity access control bypass vulnerability affecting the Linux kernel before version 4.14.6. It allows a local attacker to add keys to a keyring with only Search permission, bypassing the intended Write permission requirement, through a crafted sequence of system calls to the KEYS subsystem. The CVSS score is 3.3, indicating a low impact on integrity and no impact on confidentiality or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.14.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

3.3LOW

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 90th percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-1127.rt56.1093.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-1127.el7
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: realtime-kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2017-17807Moderate

kernel: Missing permissions check for request_key() destination allows local attackers to add keys to keyring without Write permission

Dec 8, 2017

References

git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Issue TrackingPatch
github.com / torvalds/linux/commit/4dca6ea1d9432052afb06baf2e3ae78188a4410b
Issue TrackingPatch
lists.debian.org / debian-lts-announce/2018/01/msg00004.html
usn.ubuntu.com / 3617-1
usn.ubuntu.com / 3617-2
usn.ubuntu.com / 3617-3
usn.ubuntu.com / 3619-1
usn.ubuntu.com / 3619-2
usn.ubuntu.com / 3620-1
usn.ubuntu.com / 3620-2
usn.ubuntu.com / 3632-1
debian.org / security/2017/dsa-4073
Third Party Advisory
debian.org / security/2018/dsa-4082
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.14.6
Issue TrackingMailing ListRelease Notes
securityfocus.com / bid/102301
Third Party AdvisoryVDB Entry