CVE-2017-16911

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

References

http://www.securityfocus.com/bid/102156

https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8

https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.114

https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/drivers/usb/usbip?id=2f2d0088eb93db5c649d2a5e34a3800a8a935fc5

https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html

https://secuniaresearch.flexerasoftware.com/advisories/80454/

https://secuniaresearch.flexerasoftware.com/secunia_research/2017-20/

https://usn.ubuntu.com/3619-1/

https://usn.ubuntu.com/3619-2/

https://usn.ubuntu.com/3754-1/

https://www.debian.org/security/2018/dsa-4187

https://www.spinics.net/lists/linux-usb/msg163480.html

Details

Source: MITRE

Published: 2018-01-31

Updated: 2018-08-24

Type: CWE-200

Risk Information

CVSS v2

Base Score: 1.9

Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.4

Severity: LOW

CVSS v3

Base Score: 4.7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1

Severity: MEDIUM

Tenable Plugins

View all (9 total)

IDNameProductFamilySeverity
112113Ubuntu 14.04 LTS : Linux kernel vulnerabilities (USN-3754-1)NessusUbuntu Local Security Checks
critical
109646SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1172-1)NessusSuSE Local Security Checks
high
109531Debian DLA-1369-1 : linux security update (Spectre)NessusDebian Local Security Checks
critical
109517Debian DSA-4187-1 : linux - security update (Spectre)NessusDebian Local Security Checks
critical
109360SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1080-1) (Spectre)NessusSuSE Local Security Checks
high
108878Ubuntu 14.04 LTS : linux-lts-xenial, linux-aws vulnerabilities (USN-3619-2)NessusUbuntu Local Security Checks
high
108842Ubuntu 16.04 LTS : linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities (USN-3619-1)NessusUbuntu Local Security Checks
high
108748SUSE SLES12 Security Update : kernel (SUSE-SU-2018:0848-1)NessusSuSE Local Security Checks
critical
108705SUSE SLES12 Security Update : kernel (SUSE-SU-2018:0834-1)NessusSuSE Local Security Checks
critical