UBUNTU-CVE-2017-5577
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-5577
UBUNTU-CVE-2017-5577
Summary:
Details: The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4_SUBMIT_CL ioctl call.
References: https://ubuntu.com/security/CVE-2017-5577, https://lkml.org/lkml/2017/1/17/759, https://ubuntu.com/security/notices/USN-3326-1, https://ubuntu.com/security/notices/USN-3327-1, https://ubuntu.com/security/notices/USN-3333-1, https://ubuntu.com/security/notices/USN-3342-1, https://ubuntu.com/security/notices/USN-3342-2, https://www.cve.org/CVERecord?id=CVE-2017-5577
Affected packages
Package
Name: linux-hwe
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
