299,758
Total vulnerabilities in the database
The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.3 | 3.10.105 |
| linux / linux_kernel | 4.8 | 4.8.4 |
| linux / linux_kernel | 3.2 | 3.2.84 |
| linux / linux_kernel | 3.11 | 3.12.67 |
| linux / linux_kernel | 3.13 | 3.16.39 |
| linux / linux_kernel | 3.17 | 3.18.46 |
| linux / linux_kernel | 3.19 | 4.1.37 |
| linux / linux_kernel | 4.2 | 4.4.27 |
| linux / linux_kernel | 4.5 | 4.7.10 |
| canonical / ubuntu_linux | 16.10 | 16.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |