PatchSiren cyber security CVE debrief
CVE-2017-5576 Linux CVE debrief
CVE-2017-5576 is a Linux kernel flaw in the VideoCore DRM driver that was published on 2017-02-06. A crafted VC4_SUBMIT_CL ioctl size value can trigger an integer overflow in vc4_get_bcl, creating a local denial-of-service risk and possibly other unspecified impact on affected systems.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-06
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-06
- Advisory updated
- 2026-05-13
Who should care
Linux kernel maintainers, distro security teams, and operators of systems that include the VideoCore (vc4) DRM driver should pay attention, especially where local users can access the affected device interfaces.
Technical summary
NVD describes CVE-2017-5576 as an integer overflow in vc4_get_bcl in drivers/gpu/drm/vc4/vc4_gem.c. The issue is triggered through a crafted size value in a VC4_SUBMIT_CL ioctl call. The supplied NVD criteria mark Linux kernel versions from 4.5 up to, but not including, 4.9.7 as vulnerable, and the weakness is mapped to CWE-190. The CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
High for systems running affected Linux kernels with the VC4 DRM driver enabled; prioritize patching or backporting to 4.9.7 or equivalent fixed releases.
Recommended defensive actions
- Upgrade or backport the upstream fix to Linux kernel 4.9.7 or a vendor release that includes the same patch.
- Confirm whether deployed kernels fall within the vulnerable range identified in the supplied NVD criteria (4.5 through before 4.9.7).
- Review systems that expose the VC4 DRM path to local users and restrict access to the relevant device nodes where practical.
- Use the upstream kernel commit and vendor changelog references in the supplied corpus to verify the fix is present in your build.
- Track any distro-specific advisories or backports for the affected kernel line before considering the issue resolved.
Evidence notes
The supplied NVD record lists CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and CWE-190, with vulnerable Linux kernel versions from 4.5 through before 4.9.7. The reference corpus includes the upstream Linux commit, the Linux 4.9.7 changelog, LKML and oss-security patch discussions, and a Red Hat Bugzilla tracking entry. No KEV entry is present in the provided data.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5576 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5576
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5576 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5576
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/torvalds/linux/commit/0f2ff82e11c86c05d051cae32b58226392d33bbf
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lkml.org/lkml/2017/1/17/761
[email protected] - Mailing List, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.