kernel: Information leak of x86 FPU registers
Published Oct 17, 2017
5.5
MEDIUMCVSS 3.0
EPSS 0.40%
Description
The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature, does not correctly handle attempts to set reserved bits in the xstate header via the ptrace() or rt_sigreturn() system call, allowing local users to read the FPU registers of other processes on the system, related to arch/x86/kernel/fpu/regset.c and arch/x86/kernel/fpu/signal.c.
Affected products
No data.
- ≤ 4.13.4
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.40% (0.00398) | 31.59th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.40% (0.00398) | 33.83th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.95% (0.00950) | 13.46th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.56% (0.00555) | 12.81th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.56% (0.00555) | 0.00th | v1 |
References (8)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=814fb7bb7db5433757d76f4c4502c96fc53b0b5e x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://access.redhat.com/security/cve/CVE-2017-15537 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1529302 Issue Tracking
- https://github.com/torvalds/linux/commit/814fb7bb7db5433757d76f4c4502c96fc53b0b5e x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-15537
- https://source.android.com/security/bulletin/pixel/2018-01-01 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2017-15537
| Link | Providers | Tags |
|---|---|---|
| http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=814fb7bb7db5433757d76f4c4502c96fc53b0b5e | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-15537 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1529302 | Issue Tracking | |
| https://github.com/torvalds/linux/commit/814fb7bb7db5433757d76f4c4502c96fc53b0b5e | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-15537 | ||
| https://source.android.com/security/bulletin/pixel/2018-01-01 | x_refsource_CONFIRM | |
| https://www.cve.org/CVERecord?id=CVE-2017-15537 |
Change history (0)
No recorded changes yet.