Red Hat Bugzilla – Bug 1473209
CVE-2017-11473 kernel: Buffer overflow in mp_override_legacy_irq()
Last modified: 2018-04-10 01:04:16 EDT
Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 4.12.2 allows local users to gain privileges via a crafted ACPI table. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-11473 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11473 Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dad5ab0db8deac535d03e3fe3d8f2892173fa6a4
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1473210]
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates of the Red Hat products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
This was fixed for Fedora with the 4.12.4 kernel updates
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:0654 https://access.redhat.com/errata/RHSA-2018:0654