CVE-2017-13695

The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:11

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/100497 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/100497 - Third Party Advisory, VDB Entry
References () https://github.com/acpica/acpica/pull/296/commits/37f2c716f2c6ab14c3ba557a539c3ee3224931b5 - Issue Tracking, Patch, Third Party Advisory () https://github.com/acpica/acpica/pull/296/commits/37f2c716f2c6ab14c3ba557a539c3ee3224931b5 - Issue Tracking, Patch, Third Party Advisory
References () https://patchwork.kernel.org/patch/9850567/ - Patch, Third Party Advisory () https://patchwork.kernel.org/patch/9850567/ - Patch, Third Party Advisory
References () https://usn.ubuntu.com/3696-1/ - () https://usn.ubuntu.com/3696-1/ -
References () https://usn.ubuntu.com/3696-2/ - () https://usn.ubuntu.com/3696-2/ -
References () https://usn.ubuntu.com/3762-1/ - () https://usn.ubuntu.com/3762-1/ -
References () https://usn.ubuntu.com/3762-2/ - () https://usn.ubuntu.com/3762-2/ -

Information

Published : 2017-08-25 08:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-13695

Mitre link : CVE-2017-13695

CVE.ORG link : CVE-2017-13695


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor