Candidate: CVE-2007-3513 References: Description: The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption). Ubuntu-Description: A flaw was discovered in the usblcd driver. A local attacker could cause large amounts of kernel memory consumption, leading to a denial of service. Notes: Bugs: upstream: released (2.6.22-rc7) linux-2.6: released (2.6.22-1) 2.6.18-etch-security: released (2.6.18.dfsg.1-13etch1) [bugfix/usblcd-limit-memory-consumption.patch] 2.6.8-sarge-security: ignored (2.6.8-17sarge1) "Too different" 2.4.27-sarge-security: ignored (2.4.27-10sarge6) "Too different" 2.6.15-dapper-security: released (2.6.15-28.57) 2.6.17-edgy-security: released (2.6.17.1-12.40) [85816b5fa3476f3fcf7758a1bd338d69184085d7] 2.6.20-feisty-security: released (2.6.20-16.31) [165018c61779a357d33947a2ae169148b6ab8d9f]