Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-8797 Details

Description

The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate the layout type when processing the NFSv4 pNFS GETDEVICEINFO or LAYOUTGET operand in a UDP packet from a remote attacker. This type value is uninitialized upon encountering certain error conditions. This value is used as an array index for dereferencing, which leads to an OOPS and eventually a DoS of knfsd and a soft-lockup of the whole system.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b550a32e60a4941994b437a8d662432a486235a5 CVEPatchVendor Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f961e3f2acae94b727380c0b74e2d3954d0edf79 CVEPatchVendor Advisory
https://access.redhat.com/errata/RHSA-2017:1842 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:2077 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:2437 CVEThird Party Advisory

see all 26 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-129Improper Validation of Array Index[email protected]

Affected Products

ProductVersions
linux linux kernel
>= 4.0, < 4.1.40
>= 4.2, < 4.4.70
>= 4.5, < 4.9.30
>= 4.11, < 4.11.3

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-8797
NVD Published Date:
Jul 2, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-8797 Details - Not Deferred