CVE-2017-5577: Medium severity Linux Linux kernel vulnerability
Last updated 4 October 2024
Other sources
The vc4getbcl function in drivers/gpu/drm/vc4/vc4gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4SUBMITCL ioctl call.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.133-1Fixed in 6.12.22-1 - Upgrade
Upgrade
linux/kernel (VideoCore DRM vc4)to a version that resolves this vulnerability.Fixed in 4.9.7
Event History
Frequently Asked Questions
What is CVE-2017-5577?
CVE-2017-5577 is a vulnerability in the VideoCore DRM driver in the Linux kernel before version 4.9.7.
How does CVE-2017-5577 affect the Linux kernel?
CVE-2017-5577 allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values.
What is the severity level of CVE-2017-5577?
CVE-2017-5577 has a severity level of low.
Which versions of the Linux kernel are affected by CVE-2017-5577?
The versions of the Linux kernel before version 4.9.7 are affected by CVE-2017-5577.
Where can I find more information about CVE-2017-5577?
You can find more information about CVE-2017-5577 at the following references: [1](https://lkml.org/lkml/2017/1/17/759), [2](http://www.openwall.com/lists/oss-security/2017/01/21/7), [3](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6b8ac63847bc2f958dd93c09edc941a0118992d9).