Information disclosure in Linux kernel - CVE-2017-16911
Published: February 16, 2018 / Updated: February 19, 2018
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists n the vhci_hcd driver due to insufficient security restrictions. A local attacker with a USB device attached over IP can use the affected driver to bypass security restrictions and access sensitive information, such as kernel memory addresses on the targeted system.
Affected software
Debian Linux
SUSE Linux