CVE-2017-18202 is a denial-of-service vulnerability affecting the Linux kernel before version 4.14.4, specifically within the __oom_reap_task_mm function. An attacker can trigger a copy_to_user call at a precise moment, leading to a TLB entry leak, use-after-free, or other unspecified impacts. With a CVSS score of 7.0 (High), this vulnerability requires local access and high attack complexity, but can result in high confidentiality, integrity, and availability impacts. There is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.6, < 4.9.68CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.