CVE-2017-7482 - CVE House
Back to Database
Status published High CVE-2017-7482

In the Linux kernel before version 4.12, Kerberos 5 tickets...

Vulnerability Description

In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7482

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

kernel:
Vulnerable Versions:
4.12

Timeline

Official Publish: July 30th, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)