CVE-2017-1000253
Confirmed PUBLISHEDLinux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86...
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
- CVE Published
- Oct 04, 2017
- Exploitation Reported
- Sep 09, 2024
- CVSS
- 7.8 High
- EPSS
- —
Affected Versions
292 version rows · page 1 of 12
| Vendor | Product | Version | Status |
|---|---|---|---|
| centos |
centos
|
6.0 |
Affected |
| centos |
centos
|
6.1 |
Affected |
| centos |
centos
|
6.2 |
Affected |
| centos |
centos
|
6.3 |
Affected |
| centos |
centos
|
6.4 |
Affected |
| centos |
centos
|
6.5 |
Affected |
| centos |
centos
|
6.6 |
Affected |
| centos |
centos
|
6.7 |
Affected |
| centos |
centos
|
6.8 |
Affected |
| centos |
centos
|
6.9 |
Affected |
| centos |
centos
|
7.1406 |
Affected |
| centos |
centos
|
7.1503 |
Affected |
| centos |
centos
|
7.1511 |
Affected |
| centos |
centos
|
7.1611 |
Affected |
| redhat |
enterprise_linux
|
6.0 |
Affected |
| redhat |
enterprise_linux
|
6.1 |
Affected |
| redhat |
enterprise_linux
|
6.2 |
Affected |
| redhat |
enterprise_linux
|
6.3 |
Affected |
| redhat |
enterprise_linux
|
6.4 |
Affected |
| redhat |
enterprise_linux
|
6.5 |
Affected |
| redhat |
enterprise_linux
|
6.6 |
Affected |
| redhat |
enterprise_linux
|
6.7 |
Affected |
| redhat |
enterprise_linux
|
6.8 |
Affected |
| redhat |
enterprise_linux
|
6.9 |
Affected |
| redhat |
enterprise_linux
|
7.0 |
Affected |
CVE References
- RHSA-2017:2798 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2798
- RHSA-2017:2795 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2795
- RHSA-2017:2801 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2801
- RHSA-2017:2796 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2796
- RHSA-2017:2799 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2799
Show 8 more references
- RHSA-2017:2794 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2794
- RHSA-2017:2793 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2793
- RHSA-2017:2797 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2797
- RHSA-2017:2802 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2802
- RHSA-2017:2800 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:2800
- 1039434 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1039434
- 101010 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/101010
- qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253... qualys.com · CVE Record https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2024-09-09 00:00 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitation Status
Exploited in the wild
Recorded 2024-09-09 00:00:00 UTC · CISA
Used in malware
Recorded 2024-09-09 00:00:00 UTC · CISA
Proof of concept available
Recorded 2018-06-18 15:22:01 UTC · GitHub
Weaknesses (CWE)
-
Improper Restriction of Operations within the Bounds of a Memory Buffer
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nessus | https://www.tenable.com/plugins/nessus/210304 | Jun 02, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2022-10-16 23:08:16 UTC · 2 stars
Linux Kernel 3.10.0-514.21.2.el7.x86_64 / 3.10.0-514.26.1.el7.x86_64 (CentOS 7) - SUID Position Independent Executable 'PIE' Local Privilege Escalation
github · Created 2018-06-18 15:22:01 UTC · 5 stars
Demo-ing CVE-2017-1000253 in a container
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
09:26 UTC about 1 year ago09:26 UTC · about 1 year ago
Nessus plugin available
Scanner coverage available
-
00:00 UTC almost 2 years ago00:00 UTC · almost 2 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
00:00 UTC almost 2 years ago00:00 UTC · almost 2 years ago
First public exploitation report
Exploit observed in malware
-
15:22 UTC about 8 years ago15:22 UTC · about 8 years ago
Public PoC available
Public proof-of-concept code published
-
01:00 UTC almost 9 years ago01:00 UTC · almost 9 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC almost 9 years ago00:00 UTC · almost 9 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2017-1000253
{
"cve_id": "CVE-2017-1000253",
"title": "Linux distributions that have not patched their long-term kernels with https:...",
"affected_vendor": "Linux",
"affected_product": "Kernel",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.8,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}