Bugzilla – Bug 1035693
VUL-0: CVE-2017-8061: kernel-source: drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and4.10.x before 4.10.7 inte...
Last modified: 2017-04-28 22:40:38 UTC
CVE-2017-8061 drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-8061 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8061 https://github.com/torvalds/linux/commit/67b0503db9c29b04eadfeede6bebbfe5ddad94ef https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=67b0503db9c29b04eadfeede6bebbfe5ddad94ef http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.7
CONFIG_VMAP_STACK is new in 4.9, and it's already fixed in the recent 4.10.x. We are unaffected.
Reassigned back to security team. Feel free to close.
This does not affect current SUSE or openSUSE products.