CVE-2017-10663: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
Affected products
- Linux Linux Kernel: from 3.8, before 3.18.64 (fixed in 3.18.64); from 3.19, before 4.1.44 (fixed in 4.1.44); from 4.2, before 4.4.81 (fixed in 4.4.81); from 4.5, before 4.9.42 (fixed in 4.9.42); from 4.10, before 4.12.4 (fixed in 4.12.4)
Published 2017-08-19. Last modified 2026-06-17.