CVE-2017-7277: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The TCP stack in the Linux kernel through 4.10.6 mishandles the SCM_TIMESTAMPING_OPT_STATS feature, which allows local users to obtain sensitive information from the kernel's internal socket data structures or cause a denial of service (out-of-bounds read) via crafted system calls, related to net/core/skbuff.c and net/socket.c.

Affected products

  • Linux Linux Kernel: up to and including 4.10.6

Published 2017-03-28. Last modified 2026-06-17.