kernel: load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary
Published Oct 4, 2017 ·Due Sep 30, 2024
7.8
HIGHCVSS 3.1
EPSS 10.70%
Description
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
Affected products
No data.
Configuration 1
- 6.0
- 6.1
- 6.2
- 6.3
- 6.4
- 6.5
- 6.6
- 6.7
- 6.8
- 6.9
- 7.1406
- 7.1503
- 7.1511
- 7.1611
- 6.0
- 6.1
- 6.2
- 6.3
- 6.4
- 6.5
- 6.6
- 6.7
- 6.8
- 6.9
- 7.0
- 7.1
- 7.2
- 7.3
Configuration 2
- ≥ 2.6.25 · < 3.2.70
- ≥ 3.3 · < 3.4.109
- ≥ 3.5 · < 3.10.77
- ≥ 3.11 · < 3.12.43
- ≥ 3.13 · < 3.14.41
- ≥ 3.15 · < 3.16.35
- ≥ 3.17 · < 3.18.14
- ≥ 3.19 · < 3.19.7
- ≥ 4.0 · < 4.0.2
-
- Version 6.0StatusaffectedConstraints-
- Version 6.1StatusaffectedConstraints-
- Version 6.2StatusaffectedConstraints-
- Version 6.3StatusaffectedConstraints-
- Version 6.4StatusaffectedConstraints-
- Version 6.5StatusaffectedConstraints-
- Version 6.6StatusaffectedConstraints-
- Version 6.7StatusaffectedConstraints-
- Version 6.8StatusaffectedConstraints-
- Version 6.9StatusaffectedConstraints-
- Version 7.1406StatusaffectedConstraints-
- Version 7.1503StatusaffectedConstraints-
- Version 7.1511StatusaffectedConstraints-
- Version 7.1611StatusaffectedConstraints-
- Version
-
- Version 1.0StatusaffectedConstraints<4.0.2
- Version 2.6.25StatusaffectedConstraints<3.2.70
- Version 3.11StatusaffectedConstraints<3.12.43
- Version 3.13StatusaffectedConstraints<3.14.41
- Version 3.15StatusaffectedConstraints<3.16.35
- Version 3.17StatusaffectedConstraints<3.18.14
- Version 3.19StatusaffectedConstraints<3.19.7
- Version 3.3StatusaffectedConstraints<3.4.109
- Version 3.5StatusaffectedConstraints<3.10.77
- Version
-
- Version 6.0StatusaffectedConstraints-
- Version 6.1StatusaffectedConstraints-
- Version 6.2StatusaffectedConstraints-
- Version 6.3StatusaffectedConstraints-
- Version 6.4StatusaffectedConstraints-
- Version 6.5StatusaffectedConstraints-
- Version 6.6StatusaffectedConstraints-
- Version 6.7StatusaffectedConstraints-
- Version 6.8StatusaffectedConstraints-
- Version 6.9StatusaffectedConstraints-
- Version 7.0StatusaffectedConstraints-
- Version 7.1StatusaffectedConstraints-
- Version 7.2StatusaffectedConstraints-
- Version 7.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Centos | Centos | n/a |
| |||||||||||||||||||||||||||||||||||||||||||||
| Linux | Linux Kernel | n/a |
| |||||||||||||||||||||||||||||||||||||||||||||
| Red Hat | Enterprise Linux | n/a |
|
Red Hat Enterprise Linux 5 Extended Lifecycle Support
kernel-0:2.6.18-423.el5
Fixed · RHSA-2017:2801
Red Hat Enterprise Linux 5.9 Long Life
kernel-0:2.6.18-348.34.2.el5
Fixed · RHSA-2017:2802
Red Hat Enterprise Linux 6
kernel-0:2.6.32-696.10.3.el6
Fixed · RHSA-2017:2795
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.76.1.el6
Fixed · RHSA-2017:2800
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.84.1.el6
Fixed · RHSA-2017:2799
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.85.1.el6
Fixed · RHSA-2017:2798
Red Hat Enterprise Linux 6.5 Telco Extended Update Support
kernel-0:2.6.32-431.85.1.el6
Fixed · RHSA-2017:2798
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.63.3.el6
Fixed · RHSA-2017:2797
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
kernel-0:2.6.32-504.63.3.el6
Fixed · RHSA-2017:2797
Red Hat Enterprise Linux 6.7 Extended Update Support
kernel-0:2.6.32-573.48.1.el6
Fixed · RHSA-2017:2796
Red Hat Enterprise Linux 7
kernel-0:3.10.0-693.el7
Fixed · RHSA-2017:1842
Red Hat Enterprise Linux 7.2 Extended Update Support
kernel-0:3.10.0-327.59.3.el7
Fixed · RHSA-2017:2794
Red Hat Enterprise Linux 7.3 Extended Update Support
kernel-0:3.10.0-514.32.3.el7
Fixed · RHSA-2017:2793
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | kernel-0:2.6.18-423.el5 | Fixed | RHSA-2017:2801 |
| Red Hat Enterprise Linux 5.9 Long Life | kernel-0:2.6.18-348.34.2.el5 | Fixed | RHSA-2017:2802 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-696.10.3.el6 | Fixed | RHSA-2017:2795 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.76.1.el6 | Fixed | RHSA-2017:2800 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.84.1.el6 | Fixed | RHSA-2017:2799 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.85.1.el6 | Fixed | RHSA-2017:2798 |
| Red Hat Enterprise Linux 6.5 Telco Extended Update Support | kernel-0:2.6.32-431.85.1.el6 | Fixed | RHSA-2017:2798 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.63.3.el6 | Fixed | RHSA-2017:2797 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | kernel-0:2.6.32-504.63.3.el6 | Fixed | RHSA-2017:2797 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | kernel-0:2.6.32-573.48.1.el6 | Fixed | RHSA-2017:2796 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-693.el7 | Fixed | RHSA-2017:1842 |
| Red Hat Enterprise Linux 7.2 Extended Update Support | kernel-0:3.10.0-327.59.3.el7 | Fixed | RHSA-2017:2794 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | kernel-0:3.10.0-514.32.3.el7 | Fixed | RHSA-2017:2793 |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 prior to kernel version 3.10.0-693, that is Red Hat Enterprise Linux 7.4 GA kernel version. Kernel versions after 3.10.0-693 contain the fix and are thus not vulnerable. This issue affects the Linux kernel-rt packages prior to the kernel version 3.10.0-693.rt56.617 (Red Hat Enteprise Linux for Realtime) and 3.10.0-693.2.1.rt56.585.el6rt (Red Hat Enterprise MRG 2). The latest Linux kernel-rt packages as shipped with Red Hat Enterprise Linux for Realtime and Red Hat Enterprise MRG 2 are not vulnerable. Future Linux kernel updates for the respective releases will address this issue.
Red Hat mitigation
By setting vm.legacy_va_layout to 1 we can effectively disable the exploitation of this issue by switching to the legacy mmap layout. The mmap allocations start much lower in the process address space and follow the bottom-up allocation model. As such, the initial PIE executable mapping is far from the reserved stack area and cannot interfere with the stack. 64-bit processes on Red Hat Enterprise Linux 5 are forced to use the legacy virtual address space layout regardless of the vm.legacy_va_layout value. Note: Applications that have demands for a large linear address space (such as certain databases) may be unable to handle the legacy memory layout proposed using this mitigation. We recommend to test your systems and applications before deploying this mitigation on production systems. Edit the /etc/sysctl.conf file as root, and add or amend: vm.legacy_va_layout = 1 To apply this setting, run the /sbin/sysctl -p command as the root user to reload the settings from /etc/sysctl.conf. Verify that vm.legacy_va_layout is now set to defined value: $ /sbin/sysctl vm.legacy_va_layout vm.legacy_va_layout = 1
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
Sep 9, 2024
Patch Due
Sep 30, 2024
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 10, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (45 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 10.70% (0.10695) | 95.69th | v5 (v2026.06.15) |
| Jun 15, 2026 | 10.70% (0.10695) | 95.23th | v5 (v2026.06.15) |
| Apr 22, 2026 | 56.99% (0.56988) | 98.14th | v4 (v2025.03.14) |
| Mar 4, 2026 | 54.19% (0.54194) | 97.96th | v4 (v2025.03.14) |
| Mar 1, 2026 | 51.55% (0.51548) | 97.85th | v4 (v2025.03.14) |
| Feb 25, 2026 | 54.19% (0.54194) | 97.96th | v4 (v2025.03.14) |
| Feb 12, 2026 | 58.67% (0.58668) | 98.16th | v4 (v2025.03.14) |
| Dec 18, 2025 | 57.21% (0.57207) | 98.04th | v4 (v2025.03.14) |
| Nov 27, 2025 | 54.44% (0.54439) | 97.89th | v4 (v2025.03.14) |
| Oct 19, 2025 | 55.54% (0.55537) | 97.94th | v4 (v2025.03.14) |
| Oct 18, 2025 | 52.71% (0.52714) | 97.78th | v4 (v2025.03.14) |
| Oct 4, 2025 | 55.56% (0.55565) | 98.00th | v4 (v2025.03.14) |
| Oct 1, 2025 | 56.58% (0.56576) | 98.06th | v4 (v2025.03.14) |
| Sep 4, 2025 | 55.56% (0.55565) | 98.00th | v4 (v2025.03.14) |
| Sep 1, 2025 | 56.58% (0.56576) | 98.05th | v4 (v2025.03.14) |
| Aug 4, 2025 | 55.56% (0.55565) | 97.96th | v4 (v2025.03.14) |
| Aug 1, 2025 | 56.58% (0.56576) | 98.03th | v4 (v2025.03.14) |
| Jul 4, 2025 | 55.56% (0.55565) | 97.93th | v4 (v2025.03.14) |
| Jul 1, 2025 | 56.58% (0.56576) | 97.99th | v4 (v2025.03.14) |
| Jun 15, 2025 | 55.56% (0.55565) | 97.91th | v4 (v2025.03.14) |
| Jun 6, 2025 | 52.93% (0.52929) | 97.78th | v4 (v2025.03.14) |
| Jun 4, 2025 | 55.56% (0.55565) | 97.91th | v4 (v2025.03.14) |
| Jun 1, 2025 | 56.58% (0.56576) | 97.98th | v4 (v2025.03.14) |
| May 3, 2025 | 55.21% (0.55212) | 97.91th | v4 (v2025.03.14) |
| May 1, 2025 | 53.14% (0.53142) | 97.80th | v4 (v2025.03.14) |
| Apr 15, 2025 | 54.42% (0.54424) | 97.83th | v4 (v2025.03.14) |
| Apr 3, 2025 | 57.05% (0.57055) | 97.95th | v4 (v2025.03.14) |
| Mar 30, 2025 | 63.38% (0.63377) | 98.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 55.34% (0.55336) | 97.19th | v4 (v2025.03.14) |
| Mar 28, 2025 | 63.38% (0.63377) | 98.25th | v4 (v2025.03.14) |
| Mar 27, 2025 | 55.34% (0.55336) | 97.74th | v4 (v2025.03.14) |
| Mar 20, 2025 | 63.38% (0.63377) | 98.28th | v4 (v2025.03.14) |
| Mar 19, 2025 | 55.34% (0.55336) | 97.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 63.38% (0.63377) | 98.24th | v4 (v2025.03.14) |
| Dec 17, 2024 | 10.62% (0.10622) | 95.03th | v3 (v2023.03.01) |
| Sep 10, 2024 | 6.30% (0.06297) | 93.77th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.07% (0.00072) | 31.15th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00072) | 29.11th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.55% (0.04547) | 88.83th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.55% (0.04547) | 87.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.55% (0.04547) | 74.10th | v2 (v2022.01.01) |
| Feb 3, 2022 | 11.74% (0.11741) | 88.45th | v1 |
| Jan 6, 2022 | 11.74% (0.11741) | 88.31th | v1 |
| Sep 1, 2021 | 11.74% (0.11741) | 95.65th | v1 |
| Apr 14, 2021 | 11.74% (0.11741) | 0.00th | v1 |
References (19)
- http://www.securityfocus.com/bid/101010 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039434 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2793 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2794 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2795 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2796 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2797 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2798 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2799 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2800 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2801 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2802 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000253 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1492212 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000253
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000253 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2017-1000253
- https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.