FlawAtlas
Search the atlas
UBUNTU-CVE-2017-17975 Moderate

UBUNTU-CVE-2017-17975

Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c in the Linux kernel through 4.14.10 allows attackers to cause a denial of service (system crash) or possibly have unspecified other impact by triggering failure of audio registration, because a kfree of the usbtv data structure occurs during a usbtv_video_free call, but the usbtv_video_fail label's code attempts to both access and free this data structure.

Exploit probability Not scored
Published December 29, 2017
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux-aws

12 explicit affected versions

Ubuntu:14.04:LTS linux-lts-xenial

52 explicit affected versions

Ubuntu:16.04:LTS linux

74 explicit affected versions

Ubuntu:16.04:LTS linux-aws

33 explicit affected versions

Ubuntu:16.04:LTS linux-azure

14 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

13 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

32 explicit affected versions

Ubuntu:16.04:LTS linux-kvm

13 explicit affected versions

Ubuntu:16.04:LTS linux-oem

11 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

47 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

44 explicit affected versions

Ubuntu:20.04:LTS linux-azure-fde

26 explicit affected versions

Ubuntu:20.04:LTS linux-gke

51 explicit affected versions

Ubuntu:20.04:LTS linux-raspi2

6 explicit affected versions

Ubuntu:20.04:LTS linux-riscv

12 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-riscv

23 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS linux-fips

3 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3653-1
related USN-3657-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-17975

Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c in the Linux kernel through 4.14.10 allows attackers to cause a denial of service (system crash) or possibly have unspecified other impact by triggering failure of audio registration, because a kfree of the usbtv data structure occurs during a usbtv_video_free call, but the usbtv_video_fail label's code attempts to both access and free this data structure.

View original source

05 / REFERENCES

Further evidence