PatchSiren cyber security CVE debrief
CVE-2017-6345 Linux CVE debrief
CVE-2017-6345 is a Linux kernel flaw in the LLC subsystem that was publicly disclosed on 2017-03-01. The issue affects kernel versions up to 4.9.12 and was fixed in 4.9.13. A local user can trigger a BUG_ON denial of service through crafted system calls, with the advisory also noting possible unspecified additional impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-01
- Advisory updated
- 2026-05-13
Who should care
Linux kernel maintainers, distro security teams, and operators of systems running Linux kernel 4.9.12 or earlier should prioritize this issue, especially on multi-user systems where untrusted local accounts or workloads can reach the kernel attack surface.
Technical summary
NVD classifies the issue as CWE-20 and rates it CVSS 3.0 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerable condition is in the LLC subsystem, where the kernel does not ensure that a required destructor exists in certain circumstances. The supplied references point to a fix in commit 8b74d439e1697110c5e5c600643e823eb1dd0762 and the 4.9.13 changelog. The described result is a local BUG_ON-triggered denial of service, with additional impact left unspecified in the record.
Defensive priority
High
Recommended defensive actions
- Upgrade Linux kernels to 4.9.13 or later, or use a vendor build that includes the backported fix.
- Confirm whether any deployed systems run kernel versions at or below 4.9.12.
- Apply the vendor or distribution security update referenced by your platform, such as the kernel fix or downstream advisory.
- Treat the issue as locally reachable and restrict unnecessary local access where practical until patched.
- Validate patched builds by confirming the kernel release notes or changelog include the 4.9.13 fix reference.
Evidence notes
The supplied NVD record lists Linux kernel versions through 4.9.12 as vulnerable and cites CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H with CWE-20. MITRE/NVD references include the Linux kernel commit 8b74d439e1697110c5e5c600643e823eb1dd0762, the Linux 4.9.13 changelog, and the oss-security mailing list post dated 2017-02-28, all consistent with a fix released around the CVE publication date of 2017-03-01.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6345 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6345
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6345 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6345
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/torvalds/linux/commit/8b74d439e1697110c5e5c600643e823eb1dd0762
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://usn.ubuntu.com/3754-1/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.