CVE-2017-7889: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: before 3.2.91 (fixed in 3.2.91); from 3.3, before 3.10.107 (fixed in 3.10.107); from 3.11, before 3.12.74 (fixed in 3.12.74); from 3.13, before 3.16.46 (fixed in 3.16.46); from 3.17, before 3.18.50 (fixed in 3.18.50); from 3.19, before 4.1.41 (fixed in 4.1.41); …

Published 2017-04-17. Last modified 2026-06-17.