CVE-2017-8924 PUBLISHED

The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow.

EPSS 0.11% · 29.3th percentile

Risk Scores

EPSS Score
0.11%
29.3th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-riscv0, 5.15.0-1020.23, 5.15.0-1022.26
Ubuntu:16.04:LTSlinux-aws4.4.0-1013.22, 0, 4.4.0-1001.10
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1067.70+cvm1.1, 5.4.0-1074.77+cvm1.1, 5.4.0-1073.76+cvm1.1
Ubuntu:16.04:LTSlinux-gke0, 4.4.0-1003.3, 4.4.0-1005.6
Ubuntu:20.04:LTSlinux-raspi25.3.0-1017.19, 5.4.0-1006.6, 5.4.0-1004.4
Ubuntu:16.04:LTSlinux4.4.0-15.31, 4.4.0-63.84, 4.4.0-62.83
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-72.93~14.04.1, 4.4.0-45.66~14.04.1, 4.4.0-47.68~14.04.1
Ubuntu:20.04:LTSlinux-riscv5.4.0-24.28, 5.4.0-26.30, 5.4.0-27.31
Ubuntu:20.04:LTSlinux-gke5.4.0-1104.111, 0, 5.4.0-1033.35
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1039.43, 4.4.0-1042.46, 4.4.0-1044.48
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:16.04:LTSlinux-raspi24.4.0-1021.27, 4.4.0-1003.4, 4.4.0-1004.5
Ubuntu:16.04:LTSlinux-hwe4.8.0-39.42~16.04.1, 4.10.0-30.34~16.04.1, 4.10.0-28.32~16.04.2
Ubuntu:14.04:LTSlinux3.13.0-123.172, 3.13.0-121.170, 3.13.0-119.166
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20

Timeline

References

Open in Interactive Console →