Back

MEDIUM

kernel: Information leak in completion handler in edge_bulk_in_callback function

Published May 12, 2017

Description

The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates of the Red Hat products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 12, 2017
Updated Aug 5, 2024
Reserved May 12, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 6, 2017