CVE-2017-8072: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not have the expected EIO error status for a zero-length report, which allows local users to have an unspecified impact via unknown vectors.

Affected products

  • Linux Linux Kernel: version 4.9 only; version 4.9.1 only; version 4.9.2 only; version 4.9.3 only; version 4.9.4 only; version 4.9.5 only; …

Published 2017-04-23. Last modified 2026-06-17.