Lucene search

K
redhatcveRedhat.comRH:CVE-2017-17558
HistoryDec 13, 2017 - 1:14 p.m.

CVE-2017-17558

2017-12-1313:14:33
redhat.com
access.redhat.com
22

0.0004 Low

EPSS

Percentile

10.1%

The usb_destroy_configuration() function, in ‘drivers/usb/core/config.c’ in the USB core subsystem, in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources. This allows local users to cause a denial of service, due to out-of-bounds write access, or possibly have unspecified other impact via a crafted USB device. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.