Memory corruption in Linux kernel - CVE-2017-16913

 

Memory corruption in Linux kernel - CVE-2017-16913

Published: March 28, 2018


Vulnerability identifier: #VU11312
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16913
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists in the "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) due to boundary error when handling CMD_SUBMIT packets. A local attacker can supply specially crafted USB over IP packet, trigger memory corruption and cause the service to crash.

Affected software

Linux kernel
Debian Linux
SUSE Linux

How to mitigate CVE-2017-16913

Install update from vendor's website.


External References

Related Security Bulletins