UBUNTU-CVE-2017-1000363
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a vulnerability the adversary has partial control over the command line) can overflow the parport_nr array in the following code, by appending many (>LP_NO) 'lp=none' arguments to the command line.
02 / AFFECTED SOFTWARE
Affected packages
115 explicit affected versions
32 explicit affected versions
54 explicit affected versions
12 explicit affected versions
10 explicit affected versions
17 explicit affected versions
30 explicit affected versions
27 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a vulnerability the adversary has partial control over the command line) can overflow the parport_nr array in the following code, by appending many (>LP_NO) 'lp=none' arguments to the command line.
05 / REFERENCES
Further evidence
- https://alephsecurity.com/vulns/aleph-2017023
- https://git.kernel.org/linus/3e21f4af170bebf47c187c1ff8bf155583c9f3b1
- https://ubuntu.com/security/CVE-2017-1000363
- https://ubuntu.com/security/notices/USN-3342-1
- https://ubuntu.com/security/notices/USN-3342-2
- https://ubuntu.com/security/notices/USN-3343-1
- https://ubuntu.com/security/notices/USN-3343-2
- https://ubuntu.com/security/notices/USN-3344-1
- https://ubuntu.com/security/notices/USN-3344-2
- https://ubuntu.com/security/notices/USN-3345-1
- https://www.cve.org/CVERecord?id=CVE-2017-1000363