CVE-2017-16533
Vulnerability Summary
Timeline
Description
The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.6CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.0•MEDIUM•Score: 6.6CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.38%• Percentile: 32%
Techniques & Countermeasures
- CWE-125•Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Affected Systems
- canonical•ubuntu_linux
14.04
- debian•linux
< 4.13.10-1 | < 4.13.10-1 | < 4.13.10-1 | < 4.13.10-1
- ubuntu•linux
< 3.13.0-157.207 | < 4.4.0-101.124
- ubuntu•linux-aws
< 4.4.0-1003.3 | < 4.4.0-1041.50
- ubuntu•linux-azure
< 4.13.0-1005.7
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-gcp
< 4.13.0-1002.5
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gke
< 4.4.0-1034.34 | all
- ubuntu•linux-hwe
< 4.13.0-32.35~16.04.1
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1010.15
- ubuntu•linux-lowlatency-hwe-6.11
all
- ubuntu•linux-lts-xenial
< 4.4.0-101.124~14.04.1
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1077.85 | all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1079.84
- debian•debian_linux
7.0
- linux•linux_kernel
< 3.2.95 | ≥ 3.3, < 3.16.50 | ≥ 3.17, < 3.18.76 | ≥ 3.19, < 4.1.46 | ≥ 4.2, < 4.4.93 | ≥ 4.5, < 4.9.57 | ≥ 4.10, < 4.13.8
References (13)
- https://lists.debian.org/debian-lts-announce/2017/12/msg00004.html
- https://github.com/torvalds/linux/commit/f043bfc98c193c284e2cd768fefabe18ac2fed9b
- https://usn.ubuntu.com/3754-1/
- http://www.securityfocus.com/bid/102026
- https://groups.google.com/d/msg/syzkaller/CxkJ9QZgwlM/O3IOvAaGAwAJ
- https://ubuntu.com/security/CVE-2017-16533
- https://ubuntu.com/security/notices/USN-3485-1
- https://ubuntu.com/security/notices/USN-3485-2
- https://ubuntu.com/security/notices/USN-3487-1
- https://ubuntu.com/security/notices/USN-3485-3
- https://ubuntu.com/security/notices/USN-3754-1
- https://www.cve.org/CVERecord?id=CVE-2017-16533
- https://security-tracker.debian.org/tracker/CVE-2017-16533