Bugzilla – Bug 1035691
VUL-0: CVE-2017-8062: kernel-source: drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before4.10.4 interacts inco...
Last modified: 2017-04-28 22:40:28 UTC
CVE-2017-8062 drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-8062 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8062 https://github.com/torvalds/linux/commit/606142af57dad981b78707234cfbd15f9f7b7125 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=606142af57dad981b78707234cfbd15f9f7b7125 http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.4
CONFIG_VMAP_STACK is new in 4.9, and it's already fixed in the recent 4.10.x. We are unaffected.
Reassigned back to security team. Feel free to close.
does not affect SLE or openSUSE, fixed upstream