UBUNTU-CVE-2017-5577
The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4_SUBMIT_CL ioctl call.
02 / AFFECTED SOFTWARE
Affected packages
17 explicit affected versions
44 explicit affected versions
38 explicit affected versions
43 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4_SUBMIT_CL ioctl call.
05 / REFERENCES
Further evidence
- https://lkml.org/lkml/2017/1/17/759
- https://ubuntu.com/security/CVE-2017-5577
- https://ubuntu.com/security/notices/USN-3326-1
- https://ubuntu.com/security/notices/USN-3327-1
- https://ubuntu.com/security/notices/USN-3333-1
- https://ubuntu.com/security/notices/USN-3342-1
- https://ubuntu.com/security/notices/USN-3342-2
- https://www.cve.org/CVERecord?id=CVE-2017-5577