The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.
Conclusion & alert: CVE-2017-1000370 is rated High Exploit Risk (74.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.25%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 42273 | exploit_db | edb | 2017-06-28 | Exploit-DB ↗ |
| 42274 | exploit_db | edb | 2017-06-28 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.71% | 2.25% | +0.54% |
| 2 | 2026-01-19 | 1.94% | 1.71% | -0.22% |
| 3 | 2026-01-18 | — | 1.94% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2017-1000370 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2017-1000370 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2017-1000370 |
suse
|
low | CVE-2017-1000370 severity low: SUSE including 13 source package names (kernel-default, kernel-default-base, …), 132 product×package rows across 31 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (31 product lines)): Known Not Affected 132. | https://www.suse.com/security/cve/CVE-2017-1000370/ |
ubuntu
|
medium | CVE-2017-1000370 medium priority: Ubuntu including 79 source packages (linux, linux-aws, …), 651 status rows across 11 suites (artful, bionic, focal, jammy, noble, oracular, trusty, upstream, xenial, yakkety, zesty): DNE 423, not-affected 118, released 90, ignored 20. | https://ubuntu.com/security/CVE-2017-1000370 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linux | linux_kernel | >= 4.1, < 4.1.43 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.2, < 4.4.78 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.5, < 4.9.39 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.10, < 4.11.12 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.12, < 4.12.3 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.debian.org/security/2017/dsa-3981 | Third Party Advisory |
| http://www.securityfocus.com/bid/99149 | Third Party Advisory VDB Entry |
| https://access.redhat.com/security/cve/CVE-2017-1000370 | Third Party Advisory VDB Entry |
| https://www.exploit-db.com/exploits/42273/ | Third Party Advisory VDB Entry |
| https://www.exploit-db.com/exploits/42274/ | Third Party Advisory VDB Entry |
| https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | Third Party Advisory |