CVE-2017-17741

medium
Published 2017-12-18 · Modified 2026-05-13
CVSS v3
6.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS v2
2.1
VIR risk
6.5

Description

The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.

Predictions

Exploit likelihood
65%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-17741

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-17741.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.spinics.net/lists/kvm/msg160796.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201801-4

OS impact

OSVersionStatusFixed in
arch archfixed4.14.11.a-1
suse slesaffected
debian debianbookwormfixed4.14.7-1
debian debianbullseyefixed4.14.7-1
debian debianforkyfixed4.14.7-1
debian debiansidfixed4.14.7-1
debian debiantrixiefixed4.14.7-1
debian debian9.0affected
linux linux-kernelaffected

References

CWEs

CWE-125

Verify integrity in audit chain (admin only). AS-IS.