kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
https://www.debian.org/security/2017/dsa-4073
https://usn.ubuntu.com/usn/usn-3523-2/