CVE-2017-17864: Debian Linux

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."

Affected products

  • Debian Debian Linux: version 9.0 only
  • Linux Linux Kernel: up to and including 4.14.8

Published 2017-12-27. Last modified 2026-06-17.