PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5576 Linux CVE debrief

CVE-2017-5576 is a Linux kernel flaw in the VideoCore DRM driver that was published on 2017-02-06. A crafted VC4_SUBMIT_CL ioctl size value can trigger an integer overflow in vc4_get_bcl, creating a local denial-of-service risk and possibly other unspecified impact on affected systems.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-06
Original CVE updated
2026-05-13
Advisory published
2017-02-06
Advisory updated
2026-05-13

Who should care

Linux kernel maintainers, distro security teams, and operators of systems that include the VideoCore (vc4) DRM driver should pay attention, especially where local users can access the affected device interfaces.

Technical summary

NVD describes CVE-2017-5576 as an integer overflow in vc4_get_bcl in drivers/gpu/drm/vc4/vc4_gem.c. The issue is triggered through a crafted size value in a VC4_SUBMIT_CL ioctl call. The supplied NVD criteria mark Linux kernel versions from 4.5 up to, but not including, 4.9.7 as vulnerable, and the weakness is mapped to CWE-190. The CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

Defensive priority

High for systems running affected Linux kernels with the VC4 DRM driver enabled; prioritize patching or backporting to 4.9.7 or equivalent fixed releases.

Recommended defensive actions

  • Upgrade or backport the upstream fix to Linux kernel 4.9.7 or a vendor release that includes the same patch.
  • Confirm whether deployed kernels fall within the vulnerable range identified in the supplied NVD criteria (4.5 through before 4.9.7).
  • Review systems that expose the VC4 DRM path to local users and restrict access to the relevant device nodes where practical.
  • Use the upstream kernel commit and vendor changelog references in the supplied corpus to verify the fix is present in your build.
  • Track any distro-specific advisories or backports for the affected kernel line before considering the issue resolved.

Evidence notes

The supplied NVD record lists CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and CWE-190, with vulnerable Linux kernel versions from 4.5 through before 4.9.7. The reference corpus includes the upstream Linux commit, the Linux 4.9.7 changelog, LKML and oss-security patch discussions, and a Red Hat Bugzilla tracking entry. No KEV entry is present in the provided data.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5576 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5576

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5576 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5576

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.