Linux kernel is vulnerable to arbitrary code execution attacks. An attacker could exploit a flaw in the vmw_surface_define_ioctl()
function, in the drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
file which could allows an attacker to cause integer overflow and out-of-bounds write, and cause a denial of service (system hang or crash) or possibly gain privileges.
www.securityfocus.com/bid/97177
access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/7.5_Release_Notes/index.html
access.redhat.com/errata/RHSA-2018:0676
access.redhat.com/errata/RHSA-2018:1062
access.redhat.com/security/cve/CVE-2017-13305
access.redhat.com/security/cve/CVE-2017-15274
access.redhat.com/security/updates/classification/#important
bugzilla.redhat.com/show_bug.cgi?id=1292927
bugzilla.redhat.com/show_bug.cgi?id=1401061
bugzilla.redhat.com/show_bug.cgi?id=1430418
bugzilla.redhat.com/show_bug.cgi?id=1436798
bugzilla.redhat.com/show_bug.cgi?id=1448770
bugzilla.redhat.com/show_bug.cgi?id=1452589
bugzilla.redhat.com/show_bug.cgi?id=1462329
bugzilla.redhat.com/show_bug.cgi?id=1500894
bugzilla.redhat.com/show_bug.cgi?id=1503749
bugzilla.redhat.com/show_bug.cgi?id=1506255
bugzilla.redhat.com/show_bug.cgi?id=1507270
bugzilla.redhat.com/show_bug.cgi?id=1509264
bugzilla.redhat.com/show_bug.cgi?id=1518274
bugzilla.redhat.com/show_bug.cgi?id=1518638
lists.freedesktop.org/archives/dri-devel/2017-March/137094.html