UBUNTU-CVE-2017-7261
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-7261
UBUNTU-CVE-2017-7261
Summary:
Details: The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic) via a crafted ioctl call for a /dev/dri/renderD* device.
References: https://ubuntu.com/security/CVE-2017-7261, http://marc.info/?t=149037004200005&r=1&w=2, https://bugzilla.redhat.com/show_bug.cgi?id=1435719, https://lists.freedesktop.org/archives/dri-devel/2017-March/136814.html, https://ubuntu.com/security/notices/USN-3293-1, https://ubuntu.com/security/notices/USN-3291-1, https://ubuntu.com/security/notices/USN-3291-2, https://ubuntu.com/security/notices/USN-3291-3, https://ubuntu.com/security/notices/USN-3361-1, https://ubuntu.com/security/notices/USN-3406-1, https://ubuntu.com/security/notices/USN-3406-2, https://www.cve.org/CVERecord?id=CVE-2017-7261
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
