← Vulnerability feed

Vulnerability record · CVE-2017-18017 · published 3 January 2018

CVE-2017-18017: Linux kernel xt_TCPMSS use-after-free in tcpmss_mangle_packet

Linux · Linux Kernel

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11 and 4.9.x before 4.9.36 contains a use-after-free that can corrupt memory. A remote attacker can trigger it when the xt_TCPMSS iptables target is in use, causing a denial of service or possibly other impact. The flaw is remotely reachable with no privileges or user interaction, making it a serious availability and integrity risk for exposed hosts.

9.8 CVSS 3.1 Critical EPSS 53% · top 1.1% CWE-416 · Use after free
9.8CVSS 3.1 base score, v2 10.0
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
29Affected product versions listed by NVD
65References
17 Jun 2026Last modified by NVD

Description

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote, unauthenticated use-after-free with critical CVSS and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.

What it is

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11 and 4.9.x before 4.9.36 contains a use-after-free that can corrupt memory. A remote attacker can trigger it when the xt_TCPMSS iptables target is in use, causing a denial of service or possibly other impact. The flaw is remotely reachable with no privileges or user interaction, making it a serious availability and integrity risk for exposed hosts.

Impact

An attacker can crash or destabilize the kernel, causing denial of service, and the use-after-free may allow memory corruption with unspecified further impact. No code execution is confirmed by the record.

Attack surface

Reached over the network through crafted packets processed by an iptables rule that uses the xt_TCPMSS target. The CVSS vector shows no authentication and no user interaction required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high at roughly 0.53 (98.9th percentile), and references are patch and advisory links rather than exploit reports, so active exploitation is not confirmed by this record.

What to do

  • Apply the upstream kernel patch (commit 2638fd0f92d4397884fd991d8f4925cb3f081901) or update to Linux 4.11 or 4.9.36 and later.
  • Install vendor kernel updates from Red Hat, Ubuntu, Debian, SUSE/openSUSE and other listed advisories.
  • If patching is delayed, remove or avoid iptables rules that use the xt_TCPMSS target on internet-facing hosts.
  • Restrict network exposure of systems running affected kernels and monitor for kernel panics or memory corruption symptoms.

Detection

  • Monitor kernel logs for oops, panic or use-after-free reports involving xt_TCPMSS or tcpmss_mangle_packet.
  • Audit iptables rulesets for use of the TCPMSS target on hosts running unpatched kernels.
  • Track kernel version inventory against the fixed 4.11 and 4.9.36 thresholds to find exposed systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2638fd0f92d4397884fd991d8f4925cb3f081901 PatchThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00008.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00013.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00015.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00038.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00047.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-03/msg00030.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-03/msg00067.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-03/msg00070.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-03/msg00072.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-04/msg00014.html Mailing ListThird Party Advisory
http://patchwork.ozlabs.org/patch/746618/ PatchThird Party Advisory
http://www.securityfocus.com/bid/102367 Broken LinkThird Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-3583-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-3583-2 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0676 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1062 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1130 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1170 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1319 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1737 Third Party Advisory
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1739765 Issue TrackingThird Party Advisory
https://github.com/torvalds/linux/commit/2638fd0f92d4397884fd991d8f4925cb3f081901 PatchThird Party Advisory
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html Mailing ListThird Party Advisory
https://lkml.org/lkml/2017/4/2/13 Third Party Advisory
https://support.f5.com/csp/article/K18352029 Third Party Advisory
https://usn.ubuntu.com/3583-1/ Third Party Advisory
https://usn.ubuntu.com/3583-2/ Third Party Advisory
https://www.arista.com/en/support/advisories-notices/security-advisories/4577-security-advisory-34 MitigationThird Party Advisory
https://www.debian.org/security/2018/dsa-4187 Third Party Advisory
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.36 Release NotesVendor Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2638fd0f92d4397884fd991d8f4925cb3f081901 PatchThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00008.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00013.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00015.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00038.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00047.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-03/msg00030.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-03/msg00067.html Mailing ListThird Party Advisory

Track CVE-2017-18017 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2017-18017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.