CVE-2017-8065: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
crypto/ccm.c in the Linux kernel 4.9.x and 4.10.x through 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Affected products
- Linux Linux Kernel: version 4.9 only; version 4.9.1 only; version 4.9.2 only; version 4.9.3 only; version 4.9.4 only; version 4.9.5 only; …
Published 2017-04-23. Last modified 2026-06-17.