CVE-2017-8071
MEDIUMLinux Kernel - Improper Resource Release
Title source: ruleDescription
drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock without considering that sleeping is possible in a USB HID request callback, which allows local users to cause a denial of service (deadlock) via unspecified vectors.
References (5)
Scores
CVSS v3
5.5
EPSS
0.0010
EPSS Percentile
27.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-404
Status
published
Affected Products (9)
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
n/a/n/a
Timeline
Published
Apr 23, 2017
Tracked Since
Feb 18, 2026