Out-of-bounds read in Linux kernel - CVE-2017-16912
Published: March 28, 2018
Vulnerability identifier: #VU11311
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16912
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists in the "get_pipe()" function (drivers/usb/usbip/stub_rx.c) due to out-of-bounds read. A local attacker can supply specially crafted USB over IP packet, trigger memory corruption and cause the service to crash.
The weakness exists in the "get_pipe()" function (drivers/usb/usbip/stub_rx.c) due to out-of-bounds read. A local attacker can supply specially crafted USB over IP packet, trigger memory corruption and cause the service to crash.
Affected software
Linux kernel
Debian Linux
SUSE Linux
Debian Linux
SUSE Linux
How to mitigate CVE-2017-16912
Install update from vendor's website.
External References
Related Security Bulletins
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- SUSE Linux update for the Linux Kernel
- Debian update for linux
- SUSE Linux update for the Linux Kernel