Wind River Support Network

HomeDefectsLIN10-2495
Fixed

LIN10-2495 : Security Advisory - linux - CVE-2017-16645

Created: Nov 13, 2017    Updated: Dec 3, 2018
Resolved Date: Dec 20, 2017
Found In Version: 10.17.41.1
Fix Version: 10.17.41.3
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Kernel

Description

The ims_pcu_get_cdc_union_desc function in drivers/input/misc/ims-pcu.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (ims_pcu_parse_cdc_data out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

https://nvd.nist.gov/vuln/detail/CVE-2017-16645

Other Downloads


CVEs


Live chat
Online