The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write access) or possibly have unspecified other impact via a crafted USB device.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-12-12T15:00:00
Updated: 2024-08-05T20:51:32.189Z
Reserved: 2017-12-12T00:00:00
Link: CVE-2017-17558
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-12-12T15:29:00.210
Modified: 2024-11-21T03:18:09.840
Link: CVE-2017-17558
Redhat