Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 641572 (CVE-2017-17741) - kernel: denial of service (write_mmio stack-based out-of-bounds read)
Summary: kernel: denial of service (write_mmio stack-based out-of-bounds read)
Status: RESOLVED FIXED
Alias: CVE-2017-17741
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: x86 Linux
: Normal normal (vote)
Assignee: Gentoo Kernel Security
URL: https://www.spinics.net/lists/kvm/msg...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-12-18 14:36 UTC by D'juan McDonald (domhnall)
Modified: 2022-03-26 00:37 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2017-12-18 14:36:36 UTC
CVE-2017-17741(https://nvd.nist.gov/vuln/detail/CVE-2017-17741):

The KVM implementation in the Linux kernel through 4.14.7 allows attackers to cause a denial of service (write_mmio stack-based out-of-bounds read) or possibly have unspecified other impact, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.


Gentoo Security Padawan
(Jmbailey/mbailey_j)
Comment 1 Romain Perier 2018-04-20 06:43:12 UTC
Accepted on upstream: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?h=linux-4.14.y&id=653c41ac4729261cb356ee1aff0f3f4f342be1eb . It is part of 4.14.x since 4.14.14
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-26 00:37:27 UTC
Fix in 4.9.77, 4.14.14, 4.15.