Description
In the Linux kernel before 4.12, Hisilicon Network Subsystem (HNS) does not consider the ETH_SS_PRIV_FLAGS case when retrieving sset_count data, which allows local users to cause a denial of service (buffer overflow and memory corruption) or possibly have unspecified other impact, as demonstrated by incompatibility between hns_get_sset_count and ethtool_get_strings.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4188-1 | linux security update |
EUVD |
EUVD-2017-9354 | In the Linux kernel before 4.12, Hisilicon Network Subsystem (HNS) does not consider the ETH_SS_PRIV_FLAGS case when retrieving sset_count data, which allows local users to cause a denial of service (buffer overflow and memory corruption) or possibly have unspecified other impact, as demonstrated by incompatibility between hns_get_sset_count and ethtool_get_strings. |
Ubuntu USN |
USN-3654-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3654-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3656-1 | Linux kernel (Raspberry Pi 2, Snapdragon) vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:13:49.032Z
Reserved: 2018-03-08T00:00:00.000Z
Link: CVE-2017-18222
No data.
Status : Modified
Published: 2018-03-08T14:29:00.223
Modified: 2024-11-21T03:19:36.477
Link: CVE-2017-18222
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN