CVE-2017-5123 is an insufficient input-validation vulnerability in the Linux kernel's waitid() system-call implementation affecting kernel versions 4.12 through 4.13. The infop user-pointer argument was used with unsafe_put_user() without a preceding access_ok() validation. A local unprivileged process can supply a kernel-space address as infop, causing waitid() to write result data to kernel memory. The resulting primitive is constrained in the values written but can be used for arbitrary placement of zero writes, including against credential fields.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains three main components: a Linux kernel module (lkm), a userland ICMP pinger tool, and a full-stack web application (vulnerable-app) with both backend (Node.js/Express) and frontend (React) code. The primary exploit is implemented in the lkm/lkm.c file, which is a malicious Linux kernel module. This module registers a Netfilter hook to intercept ICMP echo requests (ping packets) with a specific sequence number (25678). When such a packet is received, the module extracts the data payload and treats it as a shell command, which it executes using /bin/bash. The output of the command is written to a temporary file (/tmp/kmout_<unique_id>), read back, and then sent to the original sender in an ICMP echo reply, effectively creating a covert remote command execution and exfiltration channel over ICMP. The temporary file is deleted after use. The pinger/data-ping.c file is a userland tool to send ICMP echo requests with arbitrary data to a target host, facilitating exploitation of the kernel module. Additionally, the repository contains a vulnerable web application (vulnerable-app). The backend (server.js) exposes several API endpoints for file and directory management. Notably, the /api/file endpoint is vulnerable to command injection, as it constructs and executes a shell command using unsanitized user input (the 'content' field), allowing arbitrary command execution on the server. In summary, this repository demonstrates two distinct remote code execution vectors: (1) a kernel-level ICMP backdoor, and (2) a web application command injection vulnerability. Both provide attackers with the ability to execute arbitrary commands on the target system, with the kernel module offering a stealthy, network-based covert channel.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2017-5123, a local privilege escalation vulnerability in the Linux kernel (introduced in commit 4c48abe91be0, e.g., kernel 4.14). The exploit targets the waitid system call, which allows an unprivileged local user to write to arbitrary kernel memory, potentially overwriting sensitive structures such as process credentials. The main exploit logic is implemented in 'main.c', which creates a large number of threads to spray memory and repeatedly attempts to trigger the vulnerability by calling waitid with crafted arguments. Upon successful exploitation, the process's UID changes, and a root shell is spawned. The 'creds.py' script is a GDB helper for analyzing kernel memory and locating credential structures, aiding in exploit development and debugging. The repository also includes a Makefile for building the exploit, a GDB script for debugging, and a detailed README with setup and exploitation instructions. The exploit is intended for educational and research purposes and is not weaponized for real-world attacks.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.