kernel: Buffer overflow in mp_override_legacy_irq()
Published Jul 20, 2017
7.8
HIGHCVSS 3.1
EPSS 0.41%
Description
Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.
Affected products
No data.
Configuration 1
- < 3.2.95
- ≥ 3.3 · < 3.16.50
- ≥ 3.17 · < 3.18.63
- ≥ 3.19 · < 4.1.44
- ≥ 4.2 · < 4.4.79
- ≥ 4.5 · < 4.9.40
- ≥ 4.10 · < 4.12.4
Configuration 2
- 14.04
No data.
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-49.el7a
Fixed · RHSA-2018:0654
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Will not fix
Red Hat Enterprise MRG 2
realtime-kernel
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-49.el7a | Fixed | RHSA-2018:0654 |
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates of the Red Hat products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. This attack requires - An attacker to be able to write to the ACPI tables ( local, privileged operation and non generalized attacks) - The ability for the attacker to reboot the system ( local, privileged operation ) - The ACPI table changes to persist through reboots ( not common on cloud/serverless platforms ) - This modification to the table alone is able to possibly corrupt memory, but the corruption will not be enough alone, the corrupted affected memory will be overwritten with valid acpi struct data which also has to corrupt the memory in which a way the flaw can create abuse (HARD). - The attacker will find it significantly difficult to abuse this a flaw in early-boot as injecting code/controlled execution at this point would require privileges. If an attacker had this specific privilege, there are easier ways to gain privilege escalation.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.41% (0.00412) | 33.10th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.41% (0.00412) | 35.15th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.03% (0.01034) | 20.32th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.89% (0.00888) | 25.41th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.89% (0.00888) | 0.00th | v1 |
References (11)
- http://www.securityfocus.com/bid/100010 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0654 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-11473 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1473209 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=70ac67826602edf8c0ccb413e5ba7eacf597a60c x_refsource_MISCPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=96301209473afd3f2f274b91cb7082d161b9be65 x_refsource_CONFIRMVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=dad5ab0db8deac535d03e3fe3d8f2892173fa6a4 x_refsource_MISCPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-11473
- https://source.android.com/security/bulletin/pixel/2018-01-01 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/3754-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-11473
Change history (0)
No recorded changes yet.