CVE-2017-5897 is a critical out-of-bounds access vulnerability in the Linux kernel's ip6gre_err function, affecting various Canonical and Debian Linux distributions. This flaw allows remote attackers to trigger an out-of-bounds access via crafted GRE flags in an IPv6 packet, leading to a CVSS score of 9.8, indicating high confidentiality, integrity, and availability impacts. While no public exploit code or active exploitation has been observed, the vulnerability has garnered significant community discussion, suggesting awareness among security researchers. Despite its high severity, it is not listed in CISA's KEV catalog and has no known Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.7, < 3.10.106CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.71CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.13, < 3.16.41CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.49CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.4.50CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.