Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-16911 Details

Description

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8 CVEIssue Tracking
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.114 CVEIssue Tracking
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/drivers/usb/usbip?id=2f2d0088eb93db5c649d2a5e34a3800a8a935fc5 CVEPatchVendor Advisory
https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html CVE
https://secuniaresearch.flexerasoftware.com/advisories/80454/ CVEThird Party Advisory

see all 24 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-200Exposure of Sensitive Information to an Unauthorized Actor[email protected]

Affected Products

ProductVersions
linux linux kernel
>= 4.4.0, < 4.4.114
>= 4.9.0, < 4.9.79
>= 4.14.0, < 4.14.8

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-16911
NVD Published Date:
Jan 31, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-16911 Details - Not Deferred