First published: Fri May 12 2017(Updated: )
Last updated 29 November 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | <=4.10.3 | |
Debian | =8.0 | |
Debian | =9.0 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8924 is a vulnerability in the Linux kernel that allows local users to obtain sensitive information from uninitialized kernel memory.
This vulnerability can be exploited by using a crafted USB device (posing as an io_ti USB serial device) to trigger the edge_bulk_in_callback function in the Linux kernel.
The severity of CVE-2017-8924 is high.
The Linux kernel versions before 4.10.4 are affected by CVE-2017-8924.
To fix CVE-2017-8924, update your Linux kernel to version 4.10.4 or later.