UBUNTU-CVE-2017-7346
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-7346
UBUNTU-CVE-2017-7346
Summary:
Details: The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device.
References: https://ubuntu.com/security/CVE-2017-7346, http://marc.info/?l=linux-kernel&m=149086968410117&w=2, https://bugzilla.redhat.com/show_bug.cgi?id=1437431, https://lists.freedesktop.org/archives/dri-devel/2017-March/137429.html, http://www.openwall.com/lists/oss-security/2017/03/29/1, https://github.com/torvalds/linux/commit/ee9c4e681ec4f58e42a83cb0c22a0289ade1aacf, https://ubuntu.com/security/notices/USN-3358-1, https://ubuntu.com/security/notices/USN-3359-1, https://ubuntu.com/security/notices/USN-3360-1, https://ubuntu.com/security/notices/USN-3360-2, https://ubuntu.com/security/notices/USN-3364-1, https://ubuntu.com/security/notices/USN-3364-2, https://ubuntu.com/security/notices/USN-3364-3, https://ubuntu.com/security/notices/USN-3371-1, https://www.cve.org/CVERecord?id=CVE-2017-7346
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
