Red Hat Bugzilla – Bug 1451399
CVE-2017-8924 kernel: Information leak in completion handler in edge_bulk_in_callback function
Last modified: 2018-01-29 12:26:31 EST
The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow.
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1457217]
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates of the Red Hat products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
This was fixed for Fedora with the 4.11 rebases.