Red Hat Bugzilla – Bug 1445333
CVE-2017-8061 kernel: dvb-usb-firmware.c interacts incorrectly with the CONFIG_VMAP_STACK option
Last modified: 2018-08-28 18:16:01 EDT
drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist. Upstream patch: https://github.com/torvalds/linux/commit/67b0503db9c29b04eadfeede6bebbfe5ddad94ef