---
title: "CVE-2017-17840\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-17840?format=md
keywords: index, follow
---

# CVE-2017-17840

Publication date 27 December 2017

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2017-17840?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can
cause the iscsiuio server to abort or potentially execute code by sending
messages with incorrect lengths, which (due to lack of checking) can lead
to buffer overflows, and result in aborts (with overflow checking enabled)
or code execution. The process\_iscsid\_broadcast function in
iscsiuio/src/unix/iscsid\_ipc.c does not validate the payload length before
a write operation.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2017-17840?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| open-iscsi | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [ratliff](https://launchpad.net/~ratliff)

iscsiuio is not built on xenial, zesty, not present in trusty

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

iscsiuio package is in universe

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17840)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-17840)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-17840)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-17840)

### Other references

* <http://www.openwall.com/lists/oss-security/2017/12/13/2>
* <https://www.cve.org/CVERecord?id=CVE-2017-17840>
