Vulnerability record · CVE-2017-18017 · published 3 January 2018
CVE-2017-18017: Linux kernel xt_TCPMSS use-after-free in tcpmss_mangle_packet
Linux · Linux Kernel
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11 and 4.9.x before 4.9.36 contains a use-after-free that can corrupt memory. A remote attacker can trigger it when the xt_TCPMSS iptables target is in use, causing a denial of service or possibly other impact. The flaw is remotely reachable with no privileges or user interaction, making it a serious availability and integrity risk for exposed hosts.
Description
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote, unauthenticated use-after-free with critical CVSS and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11 and 4.9.x before 4.9.36 contains a use-after-free that can corrupt memory. A remote attacker can trigger it when the xt_TCPMSS iptables target is in use, causing a denial of service or possibly other impact. The flaw is remotely reachable with no privileges or user interaction, making it a serious availability and integrity risk for exposed hosts.
Impact
An attacker can crash or destabilize the kernel, causing denial of service, and the use-after-free may allow memory corruption with unspecified further impact. No code execution is confirmed by the record.
Attack surface
Reached over the network through crafted packets processed by an iptables rule that uses the xt_TCPMSS target. The CVSS vector shows no authentication and no user interaction required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high at roughly 0.53 (98.9th percentile), and references are patch and advisory links rather than exploit reports, so active exploitation is not confirmed by this record.
What to do
- Apply the upstream kernel patch (commit 2638fd0f92d4397884fd991d8f4925cb3f081901) or update to Linux 4.11 or 4.9.36 and later.
- Install vendor kernel updates from Red Hat, Ubuntu, Debian, SUSE/openSUSE and other listed advisories.
- If patching is delayed, remove or avoid iptables rules that use the xt_TCPMSS target on internet-facing hosts.
- Restrict network exposure of systems running affected kernels and monitor for kernel panics or memory corruption symptoms.
Detection
- Monitor kernel logs for oops, panic or use-after-free reports involving xt_TCPMSS or tcpmss_mangle_packet.
- Audit iptables rulesets for use of the TCPMSS target on hosts running unpatched kernels.
- Track kernel version inventory against the fixed 4.11 and 4.9.36 thresholds to find exposed systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-18017 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-18017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.