[Forgot Password]
Login  Register Subscribe

23631

 
 

127000

 
 

102010

 
 

909

 
 

81059

 
 

123

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2017-16914Date: (C)2018-02-07   (M)2018-02-19


The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer dereference) via a specially crafted USB over IP packet.

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score  : 5.9CVSS Score  : 7.1
Exploit Score: 2.2Exploit Score: 8.6
Impact Score : 3.6Impact Score : 6.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: COMPLETE
Integrity: NONE 
Availability: HIGH 
  





Reference:
BID-102150
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.49
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.107
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.71
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/drivers/usb/usbip?id=be6123df1ea8f01ee2f896a16c2b7be3e4557a5a
https://secuniaresearch.flexerasoftware.com/advisories/80722/
https://secuniaresearch.flexerasoftware.com/secunia_research/2017-21/
https://www.spinics.net/lists/linux-usb/msg163480.html

© 2013 SecPod Technologies