CVE-2017-14497: Debian Linux

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Linux Linux Kernel: from 4.6, before 4.9.51 (fixed in 4.9.51); from 4.10, before 4.12.14 (fixed in 4.12.14)

Published 2017-09-15. Last modified 2026-06-17.