The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Sep 25, 2017 | Jun 19, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade kernel-develUpgrade kernelUpgrade perfUpgrade kernel-oriUpgrade python-perfUpgrade kernel-headersUpgrade kernel-debuginfoUpgrade kernel-debugUpgrade kernel-tools-libsUpgrade kernel-tools | Nov 30, 2017 | Jun 19, 2017 |
| Oracle_linux | — | Upgrade kernel-uek | Jun 4, 2020 | Jun 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 19, 2017 |
| Ubuntu | — | Upgrade linux-gcpUpgrade linux-awsUpgrade linux-fipsUpgrade linux-lts-xenialUpgrade linux-raspi2Upgrade linux-gkeUpgrade linux-hwe-edgeUpgrade linux-snapdragonUpgrade linuxUpgrade linux-hwe | Nov 19, 2024 | Jun 19, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub