Bugzilla – Bug 1035689
VUL-0: CVE-2017-8063: kernel-source: drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before4.10.12 interacts inco...
Last modified: 2017-04-28 22:40:17 UTC
CVE-2017-8063 drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-8063 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8063 https://github.com/torvalds/linux/commit/3f190e3aec212fc8c61e202c51400afa7384d4bc https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3f190e3aec212fc8c61e202c51400afa7384d4bc http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.12
its been there for a while
CONFIG_VMAP_STACK is new in 4.9, and it's already fixed in the recent 4.10.x. We are unaffected.
Reassigned back to security team. Feel free to close.
upstream fix, opensuse or sle not affected.