CVE-2017-17558 PUBLISHED

The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write access) or possibly have unspecified other impact via a crafted USB device.

EPSS 0.07% · 22.0th percentile

Risk Scores

EPSS Score
0.07%
22.0th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:16.04:LTSlinux-raspi24.4.0-1065.73, 4.4.0-1059.67, 4.4.0-1040.47
Ubuntu:22.04:LTSlinux-riscv5.15.0-1027.31, 5.15.0-1026.30, 5.15.0-1023.27
Ubuntu:16.04:LTSlinux-kvm4.4.0-1004.9, 0, 4.4.0-1019.24
Ubuntu:14.04:LTSlinux-aws4.4.0-1009.9, 4.4.0-1010.10, 4.4.0-1011.11
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips0, 4.4.0-1003.3, 4.4.0-1005.5
Ubuntu:16.04:LTSlinux-gcp4.13.0-1013.17, 4.13.0-1011.15, 4.13.0-1012.16
Ubuntu:16.04:LTSlinux4.4.0-64.85, 4.4.0-91.114, 4.4.0-89.112
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1098.104+cvm1.1, 5.4.0-1100.106+cvm1.1, 5.4.0-1103.109+cvm1.1
Ubuntu:16.04:LTSlinux-aws4.4.0-1007.16, 4.4.0-1004.13, 4.4.0-1003.12
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1059.63, 0, 4.4.0-1012.12
Ubuntu:20.04:LTSlinux-raspi25.3.0-1017.19, 5.3.0-1015.17, 5.3.0-1014.16
Ubuntu:14.04:LTSlinux3.13.0-14.34, 3.13.0-15.35, 3.13.0-156.206
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-28.47~14.04.1, 4.4.0-22.40~14.04.1, 4.4.0-22.39~14.04.1
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:16.04:LTSlinux-azure4.13.0-1006.8, 4.13.0-1005.7, 4.13.0-1018.21
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:20.04:LTSlinux-riscv5.4.0-30.34, 5.4.0-31.35, 5.4.0-33.37
Ubuntu:20.04:LTSlinux-gke5.4.0-1081.87, 5.4.0-1083.89, 5.4.0-1084.90
Ubuntu:16.04:LTSlinux-hwe4.8.0-49.52~16.04.1, 0, 4.8.0-36.36~16.04.1

Timeline

References

Open in Interactive Console →