CVE-2017-18257: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Linux Linux Kernel: before 4.11 (fixed in 4.11)

Published 2018-04-04. Last modified 2026-06-17.