SB2017070415 - Memory leak in Linux kernel drm virtio driver
Published: July 4, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2017-10810)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the virtio_gpu_object_create() function in drivers/gpu/drm/virtio/virtgpu_object.c. A remote non-authenticated attacker can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://lkml.org/lkml/2017/4/6/668
- https://github.com/torvalds/linux/commit/385aee965b4e4c36551c362a334378d2985b722a
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=385aee965b4e4c36551c362a334378d2985b722a
- http://www.securityfocus.com/bid/99433
- http://www.debian.org/security/2017/dsa-3927