CVE-2017-7558 is a high-severity kernel data leak affecting Linux kernel versions 4.7-rc1 through 4.13, specifically within the inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions. This out-of-bound read can expose up to 100 bytes of slab data to userspace, potentially revealing sensitive information. The vulnerability has a CVSS score of 7.5, indicating a high impact on confidentiality with low attack complexity and no user interaction required. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.7, <= 4.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
4.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.7:rc1:*:*:*:*:*:* | ||
4.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.7:rc2:*:*:*:*:*:* | ||
4.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.7:rc3:*:*:*:*:*:* | ||
4.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.7:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.