The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.11.4 defines a backup_handle variable but does not give it an initial value. If one attempts to create a GB surface, with a previously allocated DMA buffer to be used as a backup buffer, the backup_handle variable does not get written to and is then later returned to user space, allowing local users to obtain sensitive information from uninitialized kernel memory via a crafted ioctl call.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-3927-1 linux security update
Debian DSA Debian DSA DSA-3945-1 linux security update
EUVD EUVD EUVD-2017-18536 The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.11.4 defines a backup_handle variable but does not give it an initial value. If one attempts to create a GB surface, with a previously allocated DMA buffer to be used as a backup buffer, the backup_handle variable does not get written to and is then later returned to user space, allowing local users to obtain sensitive information from uninitialized kernel memory via a crafted ioctl call.
Ubuntu USN Ubuntu USN USN-3358-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3359-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3360-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3360-2 Linux kernel (Trusty HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3364-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-3364-2 Linux kernel (Xenial HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3364-3 Linux kernel (AWS, GKE) vulnerabilities
Ubuntu USN Ubuntu USN USN-3371-1 Linux kernel (HWE) kernel vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T17:11:02.363Z

Reserved: 2017-06-13T00:00:00

Link: CVE-2017-9605

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-06-13T19:29:00.393

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-9605

cve-icon Redhat

Severity : Low

Publid Date: 2017-06-02T00:00:00Z

Links: CVE-2017-9605 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses