Revision Date: | 2017-02-06 | Version: | 1 | Title: | CVE-2017-5577 on Ubuntu 16.04 LTS (xenial) - low. | Description: | The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4_SUBMIT_CL ioctl call. Ingo Molnar discovered that the VideoCore DRM driver in the Linux kernel did not return an error after detecting certain overflows. A local attacker could exploit this issue to cause a denial of service (OOPS).
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2017-5577
| Platform(s): | Ubuntu 16.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 16.04 LTS (xenial) is installed. AND Package Information
NOT While related to the CVE in some way, the 'linux' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-aws' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-azure' package in xenial is not affected (note: '4.11.0-1009.9').
OR NOT While related to the CVE in some way, the 'linux-euclid' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-flo' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-gcp' package in xenial is not affected (note: '4.10.0-1004.4').
OR NOT While related to the CVE in some way, the 'linux-gke' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-goldfish' package in xenial is not affected.
OR The 'linux-hwe' package in xenial was vulnerable but has been fixed (note: '4.8.0-58.63~16.04.1').
OR The 'linux-hwe-edge' package in xenial was vulnerable but has been fixed (note: '4.8.0-58.63~16.04.1').
OR NOT While related to the CVE in some way, the 'linux-kvm' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-mako' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-raspi2' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-snapdragon' package in xenial is not affected.
|
|