CVE-2017-8925: Medium severity linux kernel vulnerability
Published May 12, 2017
·Updated
Last updated 29 November 2024
Other sources
The omninetopen function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
Affected Software
4 affected componentsFixes available
Linux Linux kernel<=4.10.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.128-16.12.21-1
Remediation
Event History
May 12, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:41 PM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·01:37 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:49 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2017-8925?
CVE-2017-8925 is a vulnerability that allows local users to cause a denial of service (tty exhaustion) in the Linux kernel before version 4.10.4.
2
How can the omninet_open function in drivers/usb/serial/omninet.c be exploited?
The omninet_open function in drivers/usb/serial/omninet.c can be exploited by leveraging reference count mishandling.
3
Which versions of the Linux kernel are affected by CVE-2017-8925?
The Linux kernel versions before 4.10.4 are affected by CVE-2017-8925.
4
How can I fix the CVE-2017-8925 vulnerability?
To fix the CVE-2017-8925 vulnerability, update your Linux kernel version to 4.10.4 or later.
5
Where can I find more information about CVE-2017-8925?
You can find more information about CVE-2017-8925 in the references provided: [1] [2] [3].