Security Advisory

CVE-2017-14954

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-10-01 03:00:00
Last updated 2024-09-17 00:50:43
Assigner mitre
State PUBLISHED

Description

The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call.