kernel: Divide-by-zero in __tcp_select_window
Published Sep 1, 2017
5.5
MEDIUMCVSS 3.0
EPSS 0.45%
Description
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
Affected products
No data.
- ≤ 4.11.12
No data.
Red Hat Enterprise Linux 5 Extended Lifecycle Support
kernel-0:2.6.18-433.el5
Fixed · RHSA-2018:2172
Red Hat Enterprise Linux 6
kernel-0:2.6.32-696.16.1.el6
Fixed · RHSA-2017:3200
Red Hat Enterprise Linux 7
kernel-0:3.10.0-693.5.2.el7
Fixed · RHSA-2017:2930
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-693.5.2.rt56.626.el7
Fixed · RHSA-2017:2931
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.5.2.rt56.592.el6rt
Fixed · RHSA-2017:2918
Red Hat Enterprise Linux 7
kernel-alt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | kernel-0:2.6.18-433.el5 | Fixed | RHSA-2018:2172 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-696.16.1.el6 | Fixed | RHSA-2017:3200 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-693.5.2.el7 | Fixed | RHSA-2017:2930 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-693.5.2.rt56.626.el7 | Fixed | RHSA-2017:2931 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.5.2.rt56.592.el6rt | Fixed | RHSA-2017:2918 |
| Red Hat Enterprise Linux 7 | kernel-alt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and 7 and MRG-2. Future Linux kernel updates for the respective releases may address this issue.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.45% (0.00445) | 36.48th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.45% (0.00445) | 35.23th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00078) | 20.79th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.79% (0.01789) | 35.03th | v1 |
| Jan 6, 2022 | 1.79% (0.01789) | 34.33th | v1 |
| Sep 1, 2021 | 1.79% (0.01789) | 74.21th | v1 |
| Apr 14, 2021 | 1.79% (0.01789) | 0.00th | v1 |
References (16)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=499350a5a6e7512d9ed369ed63a4244b6536f4f8 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html vendor-advisoryx_refsource_SUSE
- http://www.debian.org/security/2017/dsa-3981 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/100878 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1039549 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/errata/RHSA-2017:2918 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2930 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2931 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:3200 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:2172 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-14106 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1487295 Issue Tracking
- https://github.com/torvalds/linux/commit/499350a5a6e7512d9ed369ed63a4244b6536f4f8 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-14106
- https://www.cve.org/CVERecord?id=CVE-2017-14106
- https://www.mail-archive.com/netdev%40vger.kernel.org/msg186255.html x_refsource_CONFIRM
Change history (0)
No recorded changes yet.