CVE-2017-1000364

NameCVE-2017-1000364
DescriptionAn issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-993-1, DSA-3886-1
NVD severitymedium (attack range: local)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)wheezy3.2.78-1vulnerable
wheezy (security)3.2.93-1fixed
jessie3.16.43-2+deb8u2fixed
jessie (security)3.16.43-2+deb8u5fixed
stretch4.9.51-1fixed
stretch (security)4.9.30-2+deb9u5fixed
buster4.13.4-2fixed
sid4.13.13-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsource(unstable)4.11.6-1medium
linuxsourcejessie3.16.43-2+deb8u1mediumDSA-3886-1
linuxsourcestretch4.9.30-2+deb9u1medium
linuxsourcewheezy3.2.89-1mediumDLA-993-1

Notes

https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt

Search for package or bug name: Reporting problems