vulnerability

Amazon Linux AMI: CVE-2017-0861: Security patch for kernel (ALAS-2017-937)

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Nov 16, 2017
Added
Dec 22, 2017
Modified
Oct 14, 2022

Description

Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.

Solution

amazon-linux-upgrade-kernel

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.