CVE-2017-5897: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.
The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
Affected products
- Canonical Ubuntu Linux: version 14.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: from 3.7, before 3.10.106 (fixed in 3.10.106); from 3.11, before 3.12.71 (fixed in 3.12.71); from 3.13, before 3.16.41 (fixed in 3.16.41); from 3.17, before 3.18.49 (fixed in 3.18.49); from 3.19, before 4.4.50 (fixed in 4.4.50); from 4.5, before 4.9.11 (fixed in 4.9.11)
Published 2017-03-23. Last modified 2026-06-17.