CVE-2017-18202: Linux Kernel
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a denial of service (TLB entry leak or use-after-free) or possibly have unspecified other impact by triggering a copy_to_user call within a certain time window.
Affected products
- Linux Linux Kernel: from 4.6, before 4.9.68 (fixed in 4.9.68); from 4.10, before 4.14.4 (fixed in 4.14.4)
Published 2018-02-27. Last modified 2026-06-17.