Revision Date: | 2017-04-23 | Version: | 1 | Title: | CVE-2017-8064 on Ubuntu 16.04 LTS (xenial) - medium. | Description: | drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. It was discovered that the DVD USB framework in the Linux kernel improperly handled memory in some configurations. A local attacker could use this to cause a denial of service (system crash).
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2017-8064
| Platform(s): | Ubuntu 16.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 16.04 LTS (xenial) is installed. AND Package Information
NOT While related to the CVE in some way, the 'linux' package in xenial is not affected (note: 'no CONFIG_VMAP_STACK').
OR NOT While related to the CVE in some way, the 'linux-aws' package in xenial is not affected (note: 'no CONFIG_VMAP_STACK').
OR NOT While related to the CVE in some way, the 'linux-azure' package in xenial is not affected (note: '4.11.0-1009.9').
OR NOT While related to the CVE in some way, the 'linux-euclid' package in xenial is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-gcp' package in xenial is not affected (note: '4.10.0-1004.4').
OR NOT While related to the CVE in some way, the 'linux-gke' package in xenial is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-hwe' package in xenial is not affected (note: '4.10.0-27.30~16.04.2').
OR NOT While related to the CVE in some way, the 'linux-hwe-edge' package in xenial is not affected (note: '4.10.0-27.30~16.04.2').
OR NOT While related to the CVE in some way, the 'linux-kvm' package in xenial is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-raspi2' package in xenial is not affected (note: 'no CONFIG_VMAP_STACK').
OR NOT While related to the CVE in some way, the 'linux-snapdragon' package in xenial is not affected (note: 'no CONFIG_VMAP_STACK').
|
|