APPLIED: [PATCH 0/1][SRU][T] CVE-2017-18360: Local DoS in io_ti serial driver

Khaled Elmously khalid.elmously at canonical.com
Mon Feb 18 08:54:34 UTC 2019


On 2019-02-11 17:40:31 , Tyler Hicks wrote:
>  In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel
>  before 4.11.3, local users could cause a denial of service by
>  division-by-zero in the serial device layer by trying to set very high baud
>  rates.
> 
>  - https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-18360.html
> 
> Clean cherry pick to Trusty. Build logs are clean. I was able to ensure that
> the module loads but don't have the hardware to test the code change.
> 
> Tyler
> 
> Johan Hovold (1):
>   USB: serial: io_ti: fix div-by-zero in set_termios
> 
>  drivers/usb/serial/io_ti.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
> 
> -- 
> 2.7.4
> 
> 
> -- 
> kernel-team mailing list
> kernel-team at lists.ubuntu.com
> https://lists.ubuntu.com/mailman/listinfo/kernel-team



More information about the kernel-team mailing list