An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1200-1 | linux security update |
Debian DLA |
DLA-993-1 | linux security update |
Debian DLA |
DLA-993-2 | linux regression update |
Debian DSA |
DSA-3886-1 | linux security update |
Debian DSA |
DSA-3886-2 | linux regression update |
EUVD |
EUVD-2017-1523 | An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010). |
Ubuntu USN |
USN-3324-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3325-1 | Linux kernel (Raspberry Pi 2) vulnerability |
Ubuntu USN |
USN-3326-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3327-1 | Linux kernel (Raspberry Pi 2) vulnerability |
Ubuntu USN |
USN-3328-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3329-1 | Linux kernel (GKE) vulnerability |
Ubuntu USN |
USN-3330-1 | Linux kernel (Qualcomm Snapdragon) vulnerability |
Ubuntu USN |
USN-3331-1 | Linux kernel (AWS) vulnerability |
Ubuntu USN |
USN-3332-1 | Linux kernel (Raspberry Pi 2) vulnerability |
Ubuntu USN |
USN-3333-1 | Linux kernel (HWE) vulnerability |
Ubuntu USN |
USN-3334-1 | Linux kernel (Xenial HWE) vulnerability |
Ubuntu USN |
USN-3335-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-3335-2 | Linux kernel (Trusty HWE) vulnerability |
Ubuntu USN |
USN-3338-1 | Linux kernel vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T22:00:41.163Z
Reserved: 2017-06-19T00:00:00
Link: CVE-2017-1000364
No data.
Status : Deferred
Published: 2017-06-19T16:29:00.233
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-1000364
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN