CVE-2017-5546: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to cause a denial of service (duplicate freelist entries and system crash) or possibly have unspecified other impact in opportunistic circumstances by leveraging the selection of a large value for a random number.

Affected products

  • Linux Linux Kernel: from 4.7, before 4.9.5 (fixed in 4.9.5)

Published 2017-02-06. Last modified 2026-06-17.