Bug ID 1037994
Summary VUL-0: CVE-2017-8831: kernel-source: Double fetch problem in Linux-4.10.1 (saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c)
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter mikhail.kasimov@gmail.com
QA Contact qa-bugs@suse.de
Found By ---
Blocker ---

Ref: https://nvd.nist.gov/vuln/detail/CVE-2017-8831
===================================================
Description

The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the
Linux kernel through 4.10.14 allows local users to cause a denial of service
(out-of-bounds array access) or possibly have unspecified other impact by
changing a certain sequence-number value, aka a "double fetch" vulnerability.
===================================================

Hyperlink

[1] https://bugzilla.kernel.org/show_bug.cgi?id=195559

[2] https://bugzilla.kernel.org/show_bug.cgi?id=195559#c2 (preliminary patch)

[3] https://security-tracker.debian.org/tracker/CVE-2017-8831


You are receiving this mail because: