CISA KEV · catalog date Sep 9, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-1000253
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015).
Exploited in the wild (CISA KEV since Sep 9, 2024). NVD reports CVSS 3.1 7.8. EPSS estimates 10.7% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
- State
- PUBLISHED
- Published
- Oct 4, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
Inspect raw assertion
- Field
container- Value
- Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel PIE Stack Buffer Corruption Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel PIE Stack Buffer Corruption Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 10.7% probability · 95.48th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.106950000000; percentile 0.954750000000
FIRST EPSS · score date Aug 27, 2026 · 95.5th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
Inspect raw assertion
- Field
container- Value
- Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel PIE Stack Buffer Corruption Vulnerability
10.7% probability · 95.48th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.106950000000; percentile 0.954750000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
41 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.4"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.5"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.6"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.7"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.8"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.9"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "7.1406"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "7.1503"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "7.1511"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "7.1611"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.25", "lessThan": "3.2.70", "versionType": "custom"}, {"status": "affected", "version": "3.3", "lessThan": "3.4.109", "versionType": "custom"}, {"status": "affected", "version": "3.5", "lessThan": "3.10.77", "versionType": "custom"}, {"status": "affected", "version": "3.11", "lessThan": "3.12.43", "versionType": "custom"}, {"status": "affected", "version": "3.13", "lessThan": "3.14.41", "versionType": "custom"}, {"status": "affected", "version": "3.15", "lessThan": "3.16.35", "versionType": "custom"}, {"status": "affected", "version": "3.17", "lessThan": "3.18.14", "versionType": "custom"}, {"status": "affected", "version": "3.19", "lessThan": "3.19.7", "versionType": "custom"}, {"status": "affected", "version": "1.0", "lessThan": "4.0.2", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0"}, {"status": "affected", "version": "6.1"}, {"status": "affected", "version": "6.2"}, {"status": "affected", "version": "6.3"}, {"status": "affected", "version": "6.4"}, {"status": "affected", "version": "6.5"}, {"status": "affected", "version": "6.6"}, {"status": "affected", "version": "6.7"}, {"status": "affected", "version": "6.8"}, {"status": "affected", "version": "6.9"}, {"status": "affected", "version": "7.0"}, {"status": "affected", "version": "7.1"}, {"status": "affected", "version": "7.2"}, {"status": "affected", "version": "7.3"}]Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.