CVE-2017-17864: Debian Linux
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
Affected products
Published 2017-12-27. Last modified 2026-06-17.