CVE-2017-7979 describes a denial-of-service vulnerability in the Linux kernel versions 4.11.x through 4.11-rc7, specifically affecting the packet action API's cookie feature. This flaw, rated High (CVSS 7.8), allows a local attacker to trigger uninitialized memory access and a refcount underflow, leading to a system hang or crash through crafted "tc filter add" commands. While the potential for other impacts exists, this vulnerability does not affect stable kernel versions. There is no evidence of active exploitation, nor are there known public exploits or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.11:rc1:*:*:*:*:*:* | ||
4.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.11:rc2:*:*:*:*:*:* | ||
4.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.11:rc3:*:*:*:*:*:* | ||
4.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.11:rc4:*:*:*:*:*:* | ||
4.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:4.11:rc5:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.