CVE-2017-10810
published 2017-07-04CVE-2017-10810: Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a…
PriorityP433high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.76%
88.8th percentile
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.11.11-1 (bookworm) | linux 4.11.11-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.4.0-92.115 | 4.4.0-92.115 |
| linux | linux_kernel | >= 0 < 4.4.0-89.112 | 4.4.0-89.112 |
| linux | linux_kernel | >= 4.10 < 4.11.10 | 4.11.10 |
| linux | linux_kernel | >= 4.2 < 4.4.77 | 4.4.77 |
| linux | linux_kernel | >= 4.5 < 4.9.37 | 4.9.37 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Xenial HWE) regression
vendor_ubuntu·2017-08-16·CVSS 7.8
[HIGH] Linux kernel (Xenial HWE) regression
Title: Linux kernel (Xenial HWE) regression
Summary: USN-3378-2 introduced a regression the Linux Hardware Enablement
kernel.
USN-3392-1 fixed a regression in the Linux kernel for Ubuntu 16.04 LTS.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS.
USN-3378-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel. Unfortunately, a regression was introduced that prevented
conntrack from working correctly in some situations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a
Ubuntu
Linux kernel regression
vendor_ubuntu·2017-08-16·CVSS 7.8
[HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: USN-3378-1 introduced a regression in the Linux kernel.
USN-3378-1 fixed vulnerabilities in the Linux kernel. Unfortunately, a
regression was introduced that prevented conntrack from working
correctly in some situations. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbi
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3377-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in some situations. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2017-10810)
石磊 discovered
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-08-03·CVSS 7.8
CVE-2017-1000365 [HIGH] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3378-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
Red Hat
Kernel: virtio-gpu: memory leakage while creating gpu object
vendor_redhat·2017-04-06·CVSS 7.5
CVE-2017-10810 [HIGH] CWE-772 Kernel: virtio-gpu: memory leakage while creating gpu object
Kernel: virtio-gpu: memory leakage while creating gpu object
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with
Red Hat Enterprise Linux 7.
This has been rated as having Low security impact and is not currently
planned to be addressed in future updates. For additional information, refer
to the Red Hat Enterprise Linux Life Cycle:
https://access.redhat.com/support/policy/updates/errata/.
Pa
Debian
CVE-2017-10810: linux - Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/v...
vendor_debian·2017·CVSS 7.5
CVE-2017-10810 [HIGH] CVE-2017-10810: linux - Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/v...
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
Scope: local
bookworm: resolved (fixed in 4.11.11-1)
bullseye: resolved (fixed in 4.11.11-1)
forky: resolved (fixed in 4.11.11-1)
sid: resolved (fixed in 4.11.11-1)
trixie: resolved (fixed in 4.11.11-1)
GHSA
GHSA-pr5m-9548-wxhv: Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object
ghsa_unreviewed·2022-05-13
CVE-2017-10810 [HIGH] CWE-772 GHSA-pr5m-9548-wxhv: Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
osv·2017-08-16·CVSS 7.8
[HIGH] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon regression
USN-3378-1 fixed vulnerabilities in the Linux kernel. Unfortunately, a
regression was introduced that prevented conntrack from working
correctly in some situations. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000
OSV
linux-lts-xenial regression
osv·2017-08-16·CVSS 7.8
[HIGH] linux-lts-xenial regression
linux-lts-xenial regression
USN-3392-1 fixed a regression in the Linux kernel for Ubuntu 16.04 LTS.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS.
USN-3378-2 fixed vulnerabilities in the Linux Hardware Enablement
kernel. Unfortunately, a regression was introduced that prevented
conntrack from working correctly in some situations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered tha
OSV
linux-hwe vulnerabilities
osv·2017-08-03·CVSS 7.8
CVE-2017-7533 [HIGH] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3377-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu
16.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in so
OSV
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-08-03·CVSS 7.8
CVE-2017-7533 [HIGH] linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in some situations. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2017-10810)
石磊 discovered that the RxRPC Kerberos 5
OSV
linux-lts-xenial vulnerabilities
osv·2017-08-03·CVSS 7.8
[HIGH] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3378-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)
It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)
李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly fr
OSV
CVE-2017-10810: Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object
osv·2017-07-04·CVSS 7.5
CVE-2017-10810 [HIGH] CVE-2017-10810: Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10810 Kernel: virtio-gpu: memory leakage while creating gpu object
bugzilla·2017-07-05·CVSS 7.5
CVE-2017-10810 [HIGH] CVE-2017-10810 Kernel: virtio-gpu: memory leakage while creating gpu object
CVE-2017-10810 Kernel: virtio-gpu: memory leakage while creating gpu object
Linux kernel built with the VirtIO GPU driver(CONFIG_DRM_VIRTIO_GPU) support
is vulnerable to a memory leakage issue. It could occur while creating a virtio
gpu object in virtio_gpu_object_create().
A user/process could use this flaw to leak host kernel memory potentially
resulting in DoS.
Upstream patch:
-> https://git.kernel.org/linus/385aee965b4e4c36551c362a334378d2985b722a
Reference:
-> http://www.openwall.com/lists/oss-security/2017/07/07/2
Discussion:
Acknowledgments:
Name: Li Qiang (Qihoo 360 Gear Team)
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1468024]
---
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise
Bugzilla
CVE-2017-10810 Kernel: virtio-gpu: memory leakage while creating gpu object [fedora-all]
bugzilla·2017-07-05·CVSS 7.5
CVE-2017-10810 [HIGH] CVE-2017-10810 Kernel: virtio-gpu: memory leakage while creating gpu object [fedora-all]
CVE-2017-10810 Kernel: virtio-gpu: memory leakage while creating gpu object [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
arXiv
AddressWatcher: Sanitizer-Based Localization of Memory Leak Fixes
arxiv_fulltext·2024-08-08
AddressWatcher: Sanitizer-Based Localization of Memory Leak Fixes
AddressWatcher: Sanitizer-Based Localization of Memory Leak Fixes
## Abstract
Memory leak bugs are a major problem in C/C++ programs. They occur when memory objects are not deallocated.
Developers need to manually deallocate these objects to prevent memory leaks.
As such, several techniques have been proposed to automatically fix memory leaks.
Although proposed approaches have merit in automatically fixing memory leaks, they present limitations.
Static-based approaches attempt to trace the complete semantics of memory object across all paths. However, they have scalability-related challenges when the target program has a large number of leaked paths.
On the other hand, dynamic approaches can spell out precise semantics of memory object only on a single execution path (not considering mul
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=385aee965b4e4c36551c362a334378d2985b722ahttp://www.debian.org/security/2017/dsa-3927http://www.securityfocus.com/bid/99433https://github.com/torvalds/linux/commit/385aee965b4e4c36551c362a334378d2985b722ahttps://lkml.org/lkml/2017/4/6/668http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=385aee965b4e4c36551c362a334378d2985b722ahttp://www.debian.org/security/2017/dsa-3927http://www.securityfocus.com/bid/99433https://github.com/torvalds/linux/commit/385aee965b4e4c36551c362a334378d2985b722ahttps://lkml.org/lkml/2017/4/6/668
2017-07-04
Published