UBUNTU-CVE-2017-12190
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-12190
UBUNTU-CVE-2017-12190
Summary:
Details: The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector has small consecutive buffers belonging to the same page. The bio_add_pc_page function merges them into one, but the page reference is never dropped. This causes a memory leak and possible system lockup (exploitable against the host OS by a guest OS user, if a SCSI disk is passed through to a virtual machine) due to an out-of-memory condition.
References: https://ubuntu.com/security/CVE-2017-12190, https://bugzilla.redhat.com/show_bug.cgi?id=1495089, https://bugzilla.suse.com/show_bug.cgi?id=1062568, https://www.mail-archive.com/[email protected]/msg1495887.html, https://www.mail-archive.com/[email protected]/msg1495884.html, https://marc.info/?t=150605752800001&r=1&w=2, https://ubuntu.com/security/notices/USN-3487-1, https://ubuntu.com/security/notices/USN-3582-1, https://ubuntu.com/security/notices/USN-3582-2, https://ubuntu.com/security/notices/USN-3583-1, https://ubuntu.com/security/notices/USN-3583-2, https://www.cve.org/CVERecord?id=CVE-2017-12190
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
