CVE-2017-11600: Linux Kernel
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via an XFRM_MSG_MIGRATE xfrm Netlink message.
Affected products
- Linux Linux Kernel: from 2.6.21, before 3.2.93 (fixed in 3.2.93); from 3.3, before 3.10.108 (fixed in 3.10.108); from 3.11, before 3.18.70 (fixed in 3.18.70); from 3.19, before 4.1.45 (fixed in 4.1.45); from 4.2, before 4.4.87 (fixed in 4.4.87); from 4.5, before 4.9.48 (fixed in 4.9.48); …
Published 2017-07-24. Last modified 2026-06-17.