7.2
CVSSv2

CVE-2017-16643

Published: 07/11/2017 Updated: 24/08/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.6 | Impact Score: 5.9 | Exploitability Score: 0.7
VMScore: 642
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel prior to 4.13.11 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

A flaw was found in the patches used to fix the 'dirtycow' vulnerability (CVE-2016-5195) An attacker, able to run local code, can exploit a race condition in transparent huge pages to modify usually read-only huge pages (CVE-2017-1000405) Linux kernel Virtualization Module (CONFIG_KVM) for the Intel processor family (CONFIG_KVM_INTEL) is vulnerab ...
USN-3509-2 introduced a regression in the Linux HWE kernel for Ubuntu 1404 LTS ...
USN-3509-1 introduced a regression in the Linux kernel for Ubuntu 1604 LTS ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
The parse_hid_report_descriptor function in drivers/input/tablet/gtcoc in the Linux kernel, before 41311, allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device ...
The parse_hid_report_descriptor function in drivers/input/tablet/gtcoc in the Linux kernel before 41311 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device The issue occurs because parse_hid_report_descriptor() has a while (i < length) loop, ...