UBUNTU-CVE-2017-7187
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-7187
UBUNTU-CVE-2017-7187
Summary:
Details: The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, leading to out-of-bounds write access in the sg_write function.
References: https://ubuntu.com/security/CVE-2017-7187, https://gist.github.com/dvyukov/48ad14e84de45b0be92b7f0eda20ff1b, https://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi.git/commit/?h=4.11/scsi-fixes&id=bf33f87dd04c371ea33feb821b60d63d754e3124, https://ubuntu.com/security/notices/USN-3293-1, https://ubuntu.com/security/notices/USN-3291-1, https://ubuntu.com/security/notices/USN-3291-2, https://ubuntu.com/security/notices/USN-3291-3, https://ubuntu.com/security/notices/USN-3361-1, https://ubuntu.com/security/notices/USN-3422-1, https://ubuntu.com/security/notices/USN-3422-2, https://www.cve.org/CVERecord?id=CVE-2017-7187
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
