CVE-2017-18552 is an out-of-bounds read and write vulnerability in the rds_recv_track_latency function within the Linux kernel (specifically net/rds/af_rds.c) affecting versions prior to 4.11. This high-severity flaw (CVSS 7.8) allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impacts. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability presents a significant risk to affected Linux systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.