Out-of-bounds read in Linux kernel - CVE-2017-16912

 

Out-of-bounds read in Linux kernel - CVE-2017-16912

Published: March 28, 2018


Vulnerability identifier: #VU11311
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16912
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the "get_pipe()" function (drivers/usb/usbip/stub_rx.c) due to out-of-bounds read. A local attacker can supply specially crafted USB over IP packet, trigger memory corruption and cause the service to crash.

Affected software

Linux kernel
Debian Linux
SUSE Linux

How to mitigate CVE-2017-16912

Install update from vendor's website.


External References

Related Security Bulletins