Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 641572 (CVE-2017-17741)

Summary: kernel: denial of service (write_mmio stack-based out-of-bounds read)
Product: Gentoo Security Reporter: D'juan McDonald (domhnall) <flopwiki>
Component: KernelAssignee: Gentoo Kernel Security <security-kernel>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: x86   
OS: Linux   
URL: https://www.spinics.net/lists/kvm/msg160710.html
Whiteboard:
Package list:
Runtime testing required: ---

Description D'juan McDonald (domhnall) 2017-12-18 14:36:36 UTC
CVE-2017-17741(https://nvd.nist.gov/vuln/detail/CVE-2017-17741):

The KVM implementation in the Linux kernel through 4.14.7 allows attackers to cause a denial of service (write_mmio stack-based out-of-bounds read) or possibly have unspecified other impact, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.


Gentoo Security Padawan
(Jmbailey/mbailey_j)
Comment 1 Romain Perier 2018-04-20 06:43:12 UTC
Accepted on upstream: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?h=linux-4.14.y&id=653c41ac4729261cb356ee1aff0f3f4f342be1eb . It is part of 4.14.x since 4.14.14
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-26 00:37:27 UTC
Fix in 4.9.77, 4.14.14, 4.15.