PT-2017-3154 · Linux+3 · Linux Kernel+3
Andrey Konovalov
·
Publicado
2017-09-19
·
Atualizado
2024-07-17
·
CVE-2017-16531
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 4.13.6
Description
The issue is caused by an out-of-bounds operation in memory within the Linux kernel, specifically in the
drivers/usb/core/config.c file. This can be exploited by an attacker using a specially crafted USB device that utilizes the USB DT INTERFACE ASSOCIATION descriptor type, potentially leading to a denial of service or other unspecified impacts.Recommendations
For Linux kernel versions prior to 4.13.6, update to version 4.13.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of USB devices or disabling the
config.c functionality in the drivers/usb/core module until a patch is available. Avoid using the USB DT INTERFACE ASSOCIATION descriptor in crafted USB devices to minimize the risk of exploitation.Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Suse
Ubuntu