CVE-2017-13695
Vulnerability Summary
Timeline
Description
The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
CVSS Metrics
- v3.0•MEDIUM•Score: 5.5CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.44%• Percentile: 37%
Techniques & Countermeasures
- CWE-200•Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Affected Systems
- debian•acpica-unix
< 20180209-1 | < 20180209-1 | < 20180209-1 | < 20180209-1
- debian•linux
< 4.17.3-1 | < 4.17.3-1 | < 4.17.3-1 | < 4.17.3-1
- ubuntu•linux
all | < 4.4.0-130.156 | < 4.15.0-34.37
- ubuntu•linux-aws
< 4.4.0-1024.25 | < 4.4.0-1062.71 | < 4.15.0-1021.21
- ubuntu•linux-azure
< 4.15.0-1023.24~16.04.1 | < 4.15.0-1023.24
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-fips
< 4.4.0-1008.10
- ubuntu•linux-gcp
< 4.15.0-1019.20~16.04.1 | < 4.15.0-1019.20
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gke
all
- ubuntu•linux-hwe
< 4.15.0-34.37~16.04.1
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1029.34 | < 4.15.0-1021.21
- ubuntu•linux-lowlatency-hwe-6.11
all
- ubuntu•linux-lts-xenial
< 4.4.0-130.156~14.04.1
- ubuntu•linux-oem
< 4.15.0-1018.21
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1092.100 | < 4.15.0-1022.24 | all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1095.100 | < 4.15.0-1053.57
- linux•linux_kernel
≤ 4.12.9
References (14)
- https://usn.ubuntu.com/3696-1/
- https://usn.ubuntu.com/3762-1/
- http://www.securityfocus.com/bid/100497
- https://usn.ubuntu.com/3762-2/
- https://usn.ubuntu.com/3696-2/
- https://github.com/acpica/acpica/pull/296/commits/37f2c716f2c6ab14c3ba557a539c3ee3224931b5
- https://patchwork.kernel.org/patch/9850567/
- https://ubuntu.com/security/CVE-2017-13695
- https://ubuntu.com/security/notices/USN-3696-1
- https://ubuntu.com/security/notices/USN-3696-2
- https://ubuntu.com/security/notices/USN-3762-1
- https://ubuntu.com/security/notices/USN-3762-2
- https://www.cve.org/CVERecord?id=CVE-2017-13695
- https://security-tracker.debian.org/tracker/CVE-2017-13695