Vulnerability Intelligence Report
CVE-2017-18017
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:52.19%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| debian | debian_linux | 7.0, 8.0 |
| arista | eos | 4.20.1fx-virtual-router |
| f5 | arx | all |
| suse | caas_platform | all |
| suse | linux_enterprise_debuginfo | 11 |
| suse | linux_enterprise_module_for_public_cloud | 12 |
| suse | linux_enterprise_point_of_sale | 11 |
| suse | openstack_cloud | 6 |
| opensuse | leap | 42.3 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_high_availability | 12 |
| suse | linux_enterprise_high_availability_extension | 11 |
| suse | linux_enterprise_live_patching | 12 |
| suse | linux_enterprise_real_time_extension | 11, 12 |
| suse | linux_enterprise_server | 11, 12 |
| suse | linux_enterprise_software_development_kit | 11, 12 |
| suse | linux_enterprise_workstation_extension | 12 |
| openstack | cloud_magnum_orchestration | 7 |
| canonical | ubuntu_linux | 12.04, 14.04 |
| redhat | mrg_realtime | 2.0 |
| redhat | enterprise_linux_desktop | 6.0, 7.0 |
| redhat | enterprise_linux_eus | 7.3, 7.4, 7.6, 7.7 |
| redhat | enterprise_linux_for_real_time | 7 |
| redhat | enterprise_linux_for_real_time_for_nfv | 7 |
| redhat | enterprise_linux_server | 6.0, 7.0 |
| redhat | enterprise_linux_server_aus | 7.3, 7.4, 7.6, 7.7 |
| redhat | enterprise_linux_server_tus | 7.3, 7.4, 7.6, 7.7 |
| redhat | enterprise_linux_workstation | 6.0, 7.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
52.189%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2018-01-03T00:00:00 |
| Published | 2018-01-03T06:00:00 |
| Patch Date | 2018-01-03 |
| Last Updated | 2025-01-03T12:04:18 |
Community Chatter & Buzz