First published: Sun Apr 23 2017(Updated: )
drivers/char/virtio_console.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=4.9<4.9.24 | |
Linux Linux kernel | >=4.10<4.10.12 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-8067.
The severity of CVE-2017-8067 is not specified.
A local user can exploit CVE-2017-8067 by leveraging use of more than one stack page.
The affected software includes Linux kernel versions 4.9.x and 4.10.x before 4.10.12.
To fix CVE-2017-8067, you should update the Linux kernel to version 4.11 or later.