UBUNTU-CVE-2017-16535
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16535
UBUNTU-CVE-2017-16535
Summary:
Details: The usb_get_bos_descriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
References: https://ubuntu.com/security/CVE-2017-16535, https://github.com/torvalds/linux/commit/1c0edc3633b56000e18d82fc241e3995ca18a69e, https://groups.google.com/d/msg/syzkaller/tzdz2fTB1K0/OvjIgLSTAgAJ, https://ubuntu.com/security/notices/USN-3485-1, https://ubuntu.com/security/notices/USN-3485-2, https://ubuntu.com/security/notices/USN-3485-3, https://ubuntu.com/security/notices/USN-3507-1, https://ubuntu.com/security/notices/USN-3754-1, https://www.cve.org/CVERecord?id=CVE-2017-16535
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
