CVE-2017-10661 is a race condition in the Linux kernel timerfd implementation in fs/timerfd.c. Kernel versions prior to 4.11-rc1 do not properly synchronize might_cancel queueing during concurrent operations on a timerfd file descriptor. The race can corrupt kernel lists or produce a use-after-free condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept (POC) exploit targeting the timerfd subsystem on Android devices (armeabi-v7a and arm64-v8a architectures, API level 21+). The main code file, 'trigger.c', is a C program that creates a large number of threads to repeatedly and concurrently call timerfd_settime on a timerfd file descriptor, using different flags and timing values. This is designed to stress the kernel's timerfd implementation and potentially trigger a race condition or other vulnerability, which could result in a kernel crash or privilege escalation if the system is vulnerable. The Makefile and Android.mk files provide build and deployment instructions, including pushing the compiled binary to '/data/local/tmp/main' and executing it via adb. There are no hardcoded network endpoints or remote attack vectors; the exploit is purely local and requires shell access to the device. The repository is structured for easy building and testing on Android devices, and is typical of kernel race condition POC exploits.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel race condition caused by improper protection of might_cancel queueing.
A Linux kernel race condition caused by improper protection of might_cancel queueing.
A Linux kernel race condition involving might_cancel queue handling, fixed by the kernel-rt update for MRG Realtime 2.
Linux kernel race condition in might_cancel queue handling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.