CVE-2017-1000253 is a Linux kernel ELF-loader vulnerability in load_elf_binary() affecting unpatched long-term kernels. When PIE randomization is enabled with normal top-down address allocation, the loader maps a PIE executable immediately below mm->mmap_base without reserving sufficient address space for the entire executable. Consequently, later PT_LOAD segments can be mapped above mm->mmap_base into the address-space gap intended to separate the stack from the executable.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a local privilege escalation exploit for CVE-2017-1000253, targeting CentOS 7 systems running specific vulnerable kernel versions (3.10.0-514.21.2.el7.x86_64 and 3.10.0-514.26.1.el7.x86_64). The main file, CVE-2017-1000253.c, orchestrates the exploit by manipulating the PIE loader and writing a malicious shared object (rootshell) to the system. The rootshell.c file contains the code for the payload, which is compiled and embedded as a binary blob in rootshell.h. When the exploit is successful, it provides a root shell, allowing the attacker to execute commands as root. The exploit requires local access to the target system and does not involve network-based attack vectors. The structure is typical for a local Linux kernel exploit: a main exploit driver, a payload source, and a binary payload header.
This repository contains a working exploit for CVE-2017-1000253, a privilege escalation vulnerability in certain CentOS 7 kernel versions (3.10.0-514.21.2.el7.x86_64 and 3.10.0-514.26.1.el7.x86_64). The main exploit logic is in 'CVE-2017-1000253.c', which orchestrates the attack and writes a payload (rootshell) to '/lib64/ld-linux-x86-64.so.2'. The payload, defined in 'rootshell.c' and included as a binary blob in 'rootshell.h', is a shared object that, when executed, writes 'HACKED' to '/root/hacked.txt', demonstrating successful privilege escalation to root. The Dockerfile provides an environment for testing the exploit in a containerized CentOS 7.3.1611 system. The README.md gives detailed instructions for setting up a vulnerable environment and running the exploit. The attack vector is local privilege escalation, requiring local code execution on a vulnerable system. The exploit is operational, providing a working payload and clear demonstration of impact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.