Bugzilla – Bug 1035649
VUL-0: CVE-2017-8072: kernel-source: The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in theLinux kernel 4.9.x befor...
Last modified: 2017-04-24 08:44:28 UTC
CVE-2017-8072 The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not have the expected EIO error status for a zero-length report, which allows local users to have an unspecified impact via unknown vectors. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-8072 http://www.cvedetails.com/cve/CVE-2017-8072/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8072 https://github.com/torvalds/linux/commit/8e9faa15469ed7c7467423db4c62aeed3ff4cae3 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8e9faa15469ed7c7467423db4c62aeed3ff4cae3
only in 4.9.