CVE-2017-8062 is a denial-of-service vulnerability affecting the Linux kernel, specifically versions 4.9.x and 4.10.x before 4.10.4, within the dvb-usb driver. It arises from an incorrect interaction with the CONFIG_VMAP_STACK option when handling DMA scatterlists. This flaw allows a local attacker to trigger a system crash, memory corruption, or potentially other unspecified impacts. The vulnerability carries a CVSSv3.1 score of 7.8 (High), indicating a local attack vector with low attack complexity and requiring low privileges. Successful exploitation can lead to high impact on confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.9, < 4.9.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.10.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.