UBUNTU-CVE-2017-5549
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information by reading the log.
02 / AFFECTED SOFTWARE
Affected packages
136 explicit affected versions
21 explicit affected versions
41 explicit affected versions
1 explicit affected versions
17 explicit affected versions
20 explicit affected versions
16 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information by reading the log.
05 / REFERENCES
Further evidence
- http://seclists.org/oss-sec/2017/q1/161
- https://ubuntu.com/security/CVE-2017-5549
- https://ubuntu.com/security/notices/USN-3208-1
- https://ubuntu.com/security/notices/USN-3208-2
- https://ubuntu.com/security/notices/USN-3361-1
- https://ubuntu.com/security/notices/USN-3754-1
- https://www.cve.org/CVERecord?id=CVE-2017-5549