VDB
CVE-2017-0537
CVE-2017-0537
PUBLISHED
An information disclosure vulnerability in the kernel USB gadget driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-31614969.
EPSS 0.28% · 52.0th percentile
Risk Scores
EPSS Score
0.28%
52.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:24.04:LTS | linux-riscv-6.17 | 0, 6.17.0-14.14.1~24.04.1 |
| Ubuntu:22.04:LTS | linux-aws-6.2 | *, *, * |
| Ubuntu:Pro:FIPS:20.04:LTS | linux-aws-fips | 5.4.0-1021.21+fips2, 0 |
| Ubuntu:20.04:LTS | linux-gcp-5.13 | 5.13.0-1030.36~20.04.1, 0, 5.13.0-1008.9~20.04.3 |
| Ubuntu:20.04:LTS | linux-gcp-5.11 | 0, 5.11.0-1009.10~20.04.1, 5.11.0-1014.16~20.04.1 |
| Ubuntu:Pro:20.04:LTS | linux-riscv-5.15 | 5.15.0-1026.30~20.04.2, 5.15.0-1027.31~20.04.1, 5.15.0-1028.32~20.04.1 |
| Ubuntu:Pro:FIPS:18.04:LTS | linux-aws-fips | 0, 4.15.0-2000.4 |
| Ubuntu:24.04:LTS | linux-oem-6.8 | 6.8.0-1024.24, 6.8.0-1020.20, 6.8.0-1018.18 |
| Ubuntu:Pro:FIPS:16.04:LTS | linux-fips | 4.4.0-1120.127, 4.4.0-1102.109, 4.4.0-1104.111 |
| Ubuntu:20.04:LTS | linux-riscv-5.11 | *, *, * |
| Ubuntu:24.04:LTS | linux-oem-6.11 | 6.11.0-1013.13, 6.11.0-1012.12, 6.11.0-1009.9 |
| Ubuntu:25.10 | linux-riscv | 6.17.0-4.4.1, 6.17.0-7.7.1, 6.17.0-8.8.1 |
| Ubuntu:24.04:LTS | linux-riscv | 6.8.0-51.52.1, 6.8.0-50.51.1, 6.8.0-49.49.1 |
| Ubuntu:Pro:18.04:LTS | linux-oracle | 4.15.0-1120.131, 4.15.0-1119.130, 4.15.0-1118.129 |
| Ubuntu:Pro:18.04:LTS | linux-oracle-5.4 | 5.4.0-1112.121~18.04.4, *, * |
| Ubuntu:22.04:LTS | linux-xilinx-zynqmp | 5.15.0-1044.48, 5.15.0-1035.39, 5.15.0-1037.41 |
| Ubuntu:24.04:LTS | linux-azure-nvidia | 6.8.0-1027.30, 6.8.0-1025.27, 6.8.0-1016.17 |
| Ubuntu:22.04:LTS | linux-azure-fde-6.8 | 6.8.0-1041.48~22.04.1, 6.8.0-1044.51~22.04.1, 6.8.0-1042.49~22.04.1 |
| Ubuntu:24.04:LTS | linux-azure-fde | 6.8.0-1046.53, 6.8.0-1041.48, 6.8.0-1044.51 |
| Ubuntu:22.04:LTS | linux-gkeop | 5.15.0-1047.54, 5.15.0-1048.55, 5.15.0-1067.75 |
…and 221 more
Timeline
- Mar 8, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-0537 third-party-advisory
- https://source.android.com/security/bulletin/2017-01-01.html third-party-advisory
- https://android.googlesource.com/kernel/tegra.git/+/389b185cb2f17fff994dbdf8d4bac003d4b2b6b3%5E%21/#F0 third-party-advisory
- https://lore.kernel.org/lkml/1484647168-30135-1-git-send-email-jilin@nvidia.com/#t third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-0537 third-party-advisory