CVE-2017-12190 describes a memory leak vulnerability in the Linux kernel, specifically affecting versions prior to 4.13.8. This flaw, residing in the bio_map_user_iov and bio_unmap_user functions within block/bio.c, results from unbalanced reference counting when handling SCSI I/O vectors with small, consecutive buffers. The vulnerability is rated Medium severity (CVSS 6.5) due to its potential for a system lockup caused by an out-of-memory condition, exploitable by a guest OS user against the host if a SCSI disk is passed through. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.13.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.