Back

CRITICAL

kernel: Buffer overflow due to unbounded strcpy in ISDN I4L driver

Published Aug 9, 2017

Description

In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tree, and 4.4-stable tree.

Affected products

Remediation

Red Hat statement

This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Red Hat mitigation

The ISDN kernel module is automatically loaded when the system boots and the ISDN service is present and enabled. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Run the following commands to blacklist the ISDN module, thus preventing them from loading: ```# echo "install isdn /bin/true">> /etc/modprobe.d/disable-isdn.conf``` On RHEL 6 execute the following commands as root to check if any isdn-related services are present: ```# chkconfig --list | grep isdn``` and disable them if they are: ```# chkconfig isdn off``` (or use a name of another isdn-related service)

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 9, 2017
Updated Aug 5, 2024
Reserved Aug 9, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 3, 2017