CVE-2017-13693

medium
Published 2017-08-25 · Modified 2026-05-13
CVSS v3
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4 NEW
—
not yet in upstream
VIR risk
5.5

Description

The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.

Predictions

Exploit likelihood
55%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2017-13693 NameCVE-2017-13693 DescriptionThe acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table. SourceCVE…

CVE-2017-13693

NameCVE-2017-13693
DescriptionThe acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
acpica-unix (PTS)bullseye20200925-1.2fixed
bookworm20200925-8fixed
trixie20250404-1fixed
forky20251212-1fixed
sid20260408-1fixed
linux (PTS)bullseye5.10.223-1vulnerable
bullseye (security)5.10.257-1vulnerable
bookworm6.1.170-3vulnerable
bookworm (security)6.1.174-1vulnerable
trixie6.12.86-1vulnerable
trixie (security)6.12.90-2vulnerable
forky, sid7.0.10-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
acpica-unixsource(unstable)20180209-1unimportant
linuxsource(unstable)(unfixed)unimportant

Notes

https://patchwork.kernel.org/patch/9919053/
non-issue/no relevant security impact

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://patchwork.kernel.org/patch/9919053/non-issue/no relevant security impact

OS impact

linux Linux kernel Affected 1 release
VersionStatusFixed in
— Affected —
suse SUSE Affected 1 release
VersionStatusFixed in
— Affected —
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 20180209-1
sid Fixed 20180209-1
forky Fixed 20180209-1
bullseye Fixed 20180209-1
bookworm Fixed 20180209-1

References

CWEs

CWE-200

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.