CVE-2017-7482: Debian Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Linux Linux Kernel: before 3.2.90 (fixed in 3.2.90); from 3.3, before 3.10.108 (fixed in 3.10.108); from 3.11, before 3.16.45 (fixed in 3.16.45); from 3.17, before 3.18.59 (fixed in 3.18.59); from 3.19, before 4.1.43 (fixed in 4.1.43); from 4.2, before 4.4.75 (fixed in 4.4.75); …
  • Red Hat Enterprise Mrg: version 2.0 only

Published 2018-07-30. Last modified 2026-06-17.