CVE-2017-7495: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.

Affected products

  • Linux Linux Kernel: up to and including 4.6.1

Published 2017-05-15. Last modified 2026-06-17.