The sanitycheckckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-10663.json"
[
{
"digest": {
"function_hash": "178598378317106975661708077080729455580",
"length": 877.0
},
"signature_version": "v1",
"target": {
"file": "fs/f2fs/super.c",
"function": "sanity_check_ckpt"
},
"signature_type": "Function",
"id": "CVE-2017-10663-bf0b4f6a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@15d3042a937c13f5d9244241c7a9c8416ff6e82a",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"263744901250724522390821170382492891423",
"233435366817835412036820920219366795360",
"196976881945090839487232353773214376657",
"93274470699037392401105268824635054206",
"83293224704705644532754663662499706950",
"147383734820199510254049624006233356340",
"246471965941775944962892105038977648178"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "fs/f2fs/super.c"
},
"signature_type": "Line",
"id": "CVE-2017-10663-f37a8e85",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@15d3042a937c13f5d9244241c7a9c8416ff6e82a",
"deprecated": false
}
]