Hide Forgot
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply structure. Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=342ffc26693b528648bdc9377e51e4f2450b4860
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1757364]
This issue was fixed in upstream kernel 4.13 and never impacted any currently supported version of Fedora.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2017-18549