CVE-2017-1000253

Confirmed PUBLISHED

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86...

Linux · Kernel
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High

At a Glance

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.

ransomware cisa malware linux nessus_scanner
CVE Published
Oct 04, 2017
Exploitation Reported
Sep 09, 2024
CVSS
7.8 High
EPSS
Low complexity No user interaction

Affected Versions

292 version rows · page 1 of 12

Vendor Product Version Status
centos
centos

6.0

Affected
centos
centos

6.1

Affected
centos
centos

6.2

Affected
centos
centos

6.3

Affected
centos
centos

6.4

Affected
centos
centos

6.5

Affected
centos
centos

6.6

Affected
centos
centos

6.7

Affected
centos
centos

6.8

Affected
centos
centos

6.9

Affected
centos
centos

7.1406

Affected
centos
centos

7.1503

Affected
centos
centos

7.1511

Affected
centos
centos

7.1611

Affected
redhat
enterprise_linux

6.0

Affected
redhat
enterprise_linux

6.1

Affected
redhat
enterprise_linux

6.2

Affected
redhat
enterprise_linux

6.3

Affected
redhat
enterprise_linux

6.4

Affected
redhat
enterprise_linux

6.5

Affected
redhat
enterprise_linux

6.6

Affected
redhat
enterprise_linux

6.7

Affected
redhat
enterprise_linux

6.8

Affected
redhat
enterprise_linux

6.9

Affected
redhat
enterprise_linux

7.0

Affected

CVE References

  • RHSA-2017:2798 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2798
  • RHSA-2017:2795 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2795
  • RHSA-2017:2801 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2801
  • RHSA-2017:2796 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2796
  • RHSA-2017:2799 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2799
Show 8 more references
  • RHSA-2017:2794 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2794
  • RHSA-2017:2793 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2793
  • RHSA-2017:2797 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2797
  • RHSA-2017:2802 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2802
  • RHSA-2017:2800 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2800
  • 1039434 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1039434
  • 101010 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/101010
  • qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253... qualys.com · CVE Record https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.