An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kernel through 4.12.10 allows local users to cause a denial of service (memory corruption and system crash) by leveraging root access.
References
Link | Resource |
---|---|
https://patchwork.kernel.org/patch/9929625/ | Patch Third Party Advisory |
https://bugzilla.kernel.org/show_bug.cgi?id=194061 | Issue Tracking Third Party Advisory |
http://www.securityfocus.com/bid/100571 | |
https://lists.debian.org/debian-lts-announce/2017/12/msg00004.html | |
https://usn.ubuntu.com/3583-2/ | |
https://usn.ubuntu.com/3583-1/ |
Configurations
Information
Published : 2017-08-30 21:29
Updated : 2018-03-15 18:29
NVD link : CVE-2017-14051
Mitre link : CVE-2017-14051
JSON object : View
CWE
CWE-190
Integer Overflow or Wraparound
Products Affected
linux
- linux_kernel