UBUNTU-CVE-2017-16538
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16538
UBUNTU-CVE-2017-16538
Summary:
Details: drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing warm-start check and incorrect attach timing (dm04_lme2510_frontend_attach versus dm04_lme2510_tuner).
References: https://ubuntu.com/security/CVE-2017-16538, https://groups.google.com/d/msg/syzkaller/XwNidsl4X04/ti6I2IaRBAAJ, https://patchwork.linuxtv.org/patch/44566/, https://patchwork.linuxtv.org/patch/44567/, https://git.linuxtv.org/media_tree.git/commit/?id=7bf7a7116ed313c601307f7e585419369926ab05, https://git.linuxtv.org/media_tree.git/commit/?id=3d932ee27e852e4904647f15b64dedca51187ad7, https://ubuntu.com/security/notices/USN-3631-1, https://ubuntu.com/security/notices/USN-3631-2, https://ubuntu.com/security/notices/USN-3754-1, https://www.cve.org/CVERecord?id=CVE-2017-16538
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
