Information disclosure in Linux kernel - CVE-2017-16911

 

Information disclosure in Linux kernel - CVE-2017-16911

Published: February 16, 2018 / Updated: February 19, 2018


Vulnerability identifier: #VU10628
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16911
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists n the vhci_hcd driver due to insufficient security restrictions. A local attacker with a USB device attached over IP can use the affected driver to bypass security restrictions and access sensitive information, such as kernel memory addresses on the targeted system.


Affected software

Linux kernel
Debian Linux
SUSE Linux

How to mitigate CVE-2017-16911

Install update from vendor's website.


External References

Related Security Bulletins