The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Sep 25, 2017 | Jun 19, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade kernel-debugUpgrade kernel-debuginfoUpgrade kernel-tools-libsUpgrade kernel-toolsUpgrade python-perfUpgrade kernel-headersUpgrade perfUpgrade kernel-oriUpgrade kernelUpgrade kernel-develUpgrade kernel-debuginfo-common-x86_64 | Nov 30, 2017 | Jun 19, 2017 |
| Oracle_linux | — | Upgrade kernel-uek | Jun 4, 2020 | Jun 19, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 19, 2017 |
| Ubuntu | — | Upgrade linux-fipsUpgrade linux-lts-xenialUpgrade linux-raspi2Upgrade linux-gcpUpgrade linux-awsUpgrade linux-hweUpgrade linux-hwe-edgeUpgrade linuxUpgrade linux-snapdragonUpgrade linux-gke | Nov 19, 2024 | Jun 19, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub