{"id":"CVE-2017-15126","details":"A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly can lead to a situation where a fork event will be removed from an already freed list of events with userfaultfd_ctx_put().","modified":"2026-03-15T22:15:04.282358Z","published":"2018-01-14T06:29:00.217Z","references":[{"type":"ADVISORY","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=384632e67e0829deb8015ee6ad916b180049d252"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/102516"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0676"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1062"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2017-15126"},{"type":"ADVISORY","url":"https://github.com/torvalds/linux/commit/384632e67e0829deb8015ee6ad916b180049d252"},{"type":"ADVISORY","url":"https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.6"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1523481"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15126.json","unresolved_ranges":[{"events":[{"introduced":"4.11"},{"fixed":"4.13.6"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}