← Back

CVE-2017-1000363

nvd nist
Published: Jul 17, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a vulnerability the adversary has partial control over the command line) can overflow the parport_nr array in the following code, by appending many (>LP_NO) 'lp=none' arguments to the command line.

Affected (10)

1 product
Linux Kernel
1 product
Debian Linux
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 2.6.12 to 3.2.91
From 3.11 to 3.16.46
From 3.17 to 3.18.55
From 3.19 to 4.1.41
From 3.3 to 3.10.106
From 4.10 to 4.11.3
From 4.2 to 4.4.70
From 4.5 to 4.9.30
Version 4.12 rc1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

References (6)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.