The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.
Conclusion & alert: CVE-2017-1000371 is rated High Exploit Risk (74.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.43%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 42273 | exploit_db | edb | 2017-06-28 | Exploit-DB ↗ |
| 42276 | exploit_db | edb | 2017-06-28 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.64% | 2.43% | -0.21% |
| 2 | 2026-06-14 | 2.51% | 2.64% | +0.13% |
| 3 | 2026-06-13 | — | 2.51% | — |
Full EPSS history (23 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2017-1000371 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2017-1000371 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2017-1000371 |
suse
|
low | CVE-2017-1000371 severity low: SUSE including 13 source package names (kernel-default, kernel-default-base, …), 132 product×package rows across 31 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (31 product lines)): Known Not Affected 132. | https://www.suse.com/security/cve/CVE-2017-1000371/ |
ubuntu
|
medium | CVE-2017-1000371 medium priority: Ubuntu including 79 source packages (linux, linux-aws, …), 651 status rows across 11 suites (artful, bionic, focal, jammy, noble, oracular, trusty, upstream, xenial, yakkety, zesty): DNE 423, not-affected 118, released 90, ignored 20. | https://ubuntu.com/security/CVE-2017-1000371 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linux | linux_kernel | >= 4.1, < 4.1.43 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.2, < 4.4.78 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.5, < 4.9.39 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.10, < 4.11.12 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 4.12, < 4.12.3 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.debian.org/security/2017/dsa-3981 | Third Party Advisory |
| http://www.securityfocus.com/bid/99131 | Third Party Advisory VDB Entry |
| https://access.redhat.com/security/cve/CVE-2017-1000371 | Third Party Advisory VDB Entry |
| https://www.exploit-db.com/exploits/42273/ | Third Party Advisory VDB Entry |
| https://www.exploit-db.com/exploits/42276/ | Third Party Advisory VDB Entry |
| https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | Third Party Advisory |