-
Notifications
You must be signed in to change notification settings - Fork 31
Open
Labels
robot: ER-Flexrobot: ER-Literobot: ER-Onerobot: ER200robot: MiR100robot: MiR1000robot: MiR200robot: MiR250robot: MiR500robot: UVDseverity: high7.0 - 8.97.0 - 8.9vendor: Easy Roboticsvendor: Enabled Roboticsvendor: Mobile Industrial Robotsvendor: Robotplushttps://robotplus.es/https://robotplus.es/vendor: UVD Robotsvulnerability
Description
id: 2563
title: 'RVD#2563: The perf_cpu_time_max_percent_handler function in the Linux kernel
allows local users to cause a denial of service.'
type: vulnerability
description: The perf_cpu_time_max_percent_handler function in kernel/events/core.c
in the Linux kernel before 4.11 allows local users to cause a denial of service
(integer overflow) or possibly have unspecified other impact via a large value,
as demonstrated by an incorrect sample-rate calculation.
cwe: CWE-190
cve: CVE-2017-18255
keywords:
- MiR100, MiR200, MiR500, MiR250, MiR1000, ER200, ER-Lite, ER-Flex,
ER-One, UVD
system: MiR100:v2.8.1.1 and before, MiR200, MiR250, MiR500, MiR1000, ER200,
ER-Lite, ER-Flex, ER-One, UVD
vendor: Mobile Industrial Robots A/S, EasyRobotics, Enabled Robotics, UVD Robots
severity:
rvss-score: 8.3
rvss-vector: RVSS:1.0/AV:L/AC:L/PR:L/UI:N/Y:T/S:U/C:H/I:H/A:H/H:U
severity-description: High
cvss-score: 7.8
cvss-vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
links:
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-18255
- https://github.com/aliasrobotics/RVD/issues/2563
flaw:
phase: runtime-operation
specificity: general issue
architectural-location: platform code
application: Linux
subsystem: kernel
package: linux-image-generic 4.4.0.62.65 amd64
languages: C
date-detected: 2020-04-23
detected-by: Offensive Team (Alias Robotics)
detected-by-method: Testing Static, Alurity:test_vulners
date-reported: '2020-06-24'
reported-by: "Victor Mayoral Vilches (Alias Robotics)"
reported-by-relationship: null
issue: https://github.com/aliasrobotics/RVD/issues/2563
reproducibility: Always
trace: Not disclosed
reproduction: Not disclosed
reproduction-image: Not disclosed
exploitation:
description: Not disclosed
exploitation-image: Not disclosed
exploitation-vector: Not disclosed
exploitation-recipe: ''
mitigation:
description: Not disclosed
pull-request: Not disclosed
date-mitigation: null
Metadata
Metadata
Assignees
Labels
robot: ER-Flexrobot: ER-Literobot: ER-Onerobot: ER200robot: MiR100robot: MiR1000robot: MiR200robot: MiR250robot: MiR500robot: UVDseverity: high7.0 - 8.97.0 - 8.9vendor: Easy Roboticsvendor: Enabled Roboticsvendor: Mobile Industrial Robotsvendor: Robotplushttps://robotplus.es/https://robotplus.es/vendor: UVD Robotsvulnerability