CVE-2018-5750
CVSS2.1
发布时间 :2018-01-26 14:29:00
修订时间 :2018-07-12 21:29:03
NMP    

[原文]The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call.


[CNNVD]CNNVD数据暂缺。


[机译]译文暂缺.

- CVSS (基础分值)

CVSS分值: 2.1 [轻微(LOW)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: LOCAL [漏洞利用需要具有物理访问权限或本地帐户]
身份认证: NONE [漏洞利用无需身份认证]

- CWE (弱点类目)

CWE-200 [信息暴露]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5750
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-5750
(官方数据源) NVD

- 其它链接及资源

http://www.securitytracker.com/id/1040319
(VENDOR_ADVISORY)  SECTRACK  1040319
https://access.redhat.com/errata/RHSA-2018:0676
(UNKNOWN)  REDHAT  RHSA-2018:0676
https://access.redhat.com/errata/RHSA-2018:1062
(UNKNOWN)  REDHAT  RHSA-2018:1062
https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html
(UNKNOWN)  MLIST  [debian-lts-announce] 20180502 [SECURITY] [DLA 1369-1] linux security update
https://patchwork.kernel.org/patch/10174835/
(VENDOR_ADVISORY)  CONFIRM  https://patchwork.kernel.org/patch/10174835/
https://usn.ubuntu.com/3631-1/
(UNKNOWN)  UBUNTU  USN-3631-1
https://usn.ubuntu.com/3631-2/
(UNKNOWN)  UBUNTU  USN-3631-2
https://usn.ubuntu.com/3697-1/
(UNKNOWN)  UBUNTU  USN-3697-1
https://usn.ubuntu.com/3697-2/
(UNKNOWN)  UBUNTU  USN-3697-2
https://usn.ubuntu.com/3698-1/
(UNKNOWN)  UBUNTU  USN-3698-1
https://usn.ubuntu.com/3698-2/
(UNKNOWN)  UBUNTU  USN-3698-2
https://www.debian.org/security/2018/dsa-4120
(UNKNOWN)  DEBIAN  DSA-4120
https://www.debian.org/security/2018/dsa-4187
(UNKNOWN)  DEBIAN  DSA-4187

- 漏洞信息 (F147146)

Red Hat Security Advisory 2018-1062-01 (PacketStormID:F147146)
2018-04-11 00:00:00
Red Hat  
advisory,denial of service,overflow,kernel,vulnerability
linux,redhat
CVE-2016-3672,CVE-2016-7913,CVE-2016-8633,CVE-2017-1000252,CVE-2017-1000407,CVE-2017-1000410,CVE-2017-12154,CVE-2017-12190,CVE-2017-13166,CVE-2017-14140,CVE-2017-15116,CVE-2017-15121,CVE-2017-15126,CVE-2017-15127,CVE-2017-15129,CVE-2017-15265,CVE-2017-17448,CVE-2017-17449,CVE-2017-17558,CVE-2017-18017,CVE-2017-18203,CVE-2017-7294,CVE-2017-8824,CVE-2017-9725,CVE-2018-1000004,CVE-2018-5750
[点击下载]

Red Hat Security Advisory 2018-1062-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Issues addressed include buffer overflow, bypass, denial of service, randomization, and use-after-free vulnerabilities.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: kernel security, bug fix, and enhancement update
Advisory ID:       RHSA-2018:1062-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:1062
Issue date:        2018-04-10
CVE Names:         CVE-2016-3672 CVE-2016-7913 CVE-2016-8633 
                   CVE-2017-7294 CVE-2017-8824 CVE-2017-9725 
                   CVE-2017-12154 CVE-2017-12190 CVE-2017-13166 
                   CVE-2017-14140 CVE-2017-15116 CVE-2017-15121 
                   CVE-2017-15126 CVE-2017-15127 CVE-2017-15129 
                   CVE-2017-15265 CVE-2017-17448 CVE-2017-17449 
                   CVE-2017-17558 CVE-2017-18017 CVE-2017-18203 
                   CVE-2017-1000252 CVE-2017-1000407 CVE-2017-1000410 
                   CVE-2018-5750 CVE-2018-6927 CVE-2018-1000004 
=====================================================================

1. Summary:

An update for kernel is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64

3. Description:

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security Fix(es):

* hw: cpu: speculative execution permission faults handling (CVE-2017-5754,
Important, KVM for Power)

* kernel: Buffer overflow in firewire driver via crafted incoming packets
(CVE-2016-8633, Important)

* kernel: Use-after-free vulnerability in DCCP socket (CVE-2017-8824,
Important)

* Kernel: kvm: nVMX: L2 guest could access hardware(L0) CR8 register
(CVE-2017-12154, Important)

* kernel: v4l2: disabled memory access protection mechanism allowing
privilege escalation (CVE-2017-13166, Important)

* kernel: media: use-after-free in [tuner-xc2028] media driver
(CVE-2016-7913, Moderate)

* kernel: drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl()
(CVE-2017-7294, Moderate)

* kernel: Incorrect type conversion for size during dma allocation
(CVE-2017-9725, Moderate)

* kernel: memory leak when merging buffers in SCSI IO vectors
(CVE-2017-12190, Moderate)

* kernel: vfs: BUG in truncate_inode_pages_range() and fuse client
(CVE-2017-15121, Moderate)

* kernel: Use-after-free in userfaultfd_event_wait_completion function in
userfaultfd.c (CVE-2017-15126, Moderate)

* kernel: net: double-free and memory corruption in get_net_ns_by_id()
(CVE-2017-15129, Moderate)

* kernel: Use-after-free in snd_seq_ioctl_create_port() (CVE-2017-15265,
Moderate)

* kernel: Missing capabilities check in net/netfilter/nfnetlink_cthelper.c
allows for unprivileged access to systemwide nfnl_cthelper_list structure
(CVE-2017-17448, Moderate)

* kernel: Missing namespace check in net/netlink/af_netlink.c allows for
network monitors to observe systemwide activity (CVE-2017-17449, Moderate)

* kernel: Unallocated memory access by malicious USB device via
bNumInterfaces overflow (CVE-2017-17558, Moderate)

* kernel: netfilter: use-after-free in tcpmss_mangle_packet function in
net/netfilter/xt_TCPMSS.c (CVE-2017-18017, Moderate)

* kernel: Race condition in drivers/md/dm.c:dm_get_from_kobject() allows
local users to cause a denial of service (CVE-2017-18203, Moderate)

* kernel: kvm: Reachable BUG() on out-of-bounds guest IRQ
(CVE-2017-1000252, Moderate)

* Kernel: KVM: DoS via write flood to I/O port 0x80 (CVE-2017-1000407,
Moderate)

* kernel: Stack information leak in the EFS element (CVE-2017-1000410,
Moderate)

* kernel: Kernel address information leak in
drivers/acpi/sbshc.c:acpi_smbus_hc_add() function potentially allowing
KASLR bypass (CVE-2018-5750, Moderate)

* kernel: Race condition in sound system can lead to denial of service
(CVE-2018-1000004, Moderate)

 * kernel: multiple Low security impact security issues (CVE-2016-3672,
CVE-2017-14140, CVE-2017-15116, CVE-2017-15127, CVE-2018-6927, Low)

Red Hat would like to thank Eyal Itkin for reporting CVE-2016-8633; Google
Project Zero for reporting CVE-2017-5754; Mohamed Ghannam for reporting
CVE-2017-8824; Jim Mattson (Google.com) for reporting CVE-2017-12154;
Vitaly Mayatskih for reporting CVE-2017-12190; Andrea Arcangeli
(Engineering) for reporting CVE-2017-15126; Kirill Tkhai for reporting
CVE-2017-15129; Jan H. SchAPnherr (Amazon) for reporting CVE-2017-1000252;
and Armis Labs for reporting CVE-2017-1000410. The CVE-2017-15121 issue was
discovered by Miklos Szeredi (Red Hat) and the CVE-2017-15116 issue was
discovered by ChunYu Wang (Red Hat).

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.5 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

5. Bugs fixed (https://bugzilla.redhat.com/):

1132610 - nfsd does not release free space of a file created with dd oflag=direct where there was no space left on device even after manual deletion
1324749 - CVE-2016-3672 kernel: unlimiting the stack disables ASLR
1334439 - Unable to disable IPv6 DAD or Optimistic DAD for all interfaces
1372079 - ixgbe nic is falsely advertising MII support
1391490 - CVE-2016-8633 kernel: Buffer overflow in firewire driver via crafted incoming packets
1402885 - CVE-2016-7913 kernel: media: use-after-free in [tuner-xc2028] media driver
1436798 - CVE-2017-7294 kernel: drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl()
1450205 - Gratuitous ARP updates received in span of 2-3 seconds time frame are all ignored
1458032 - [Intel 7.5 Bug] KVMGT: Bogus PCI BAR emulation
1460213 - cls_matchall: kernel panic when used with classful qdiscs
1461282 - kernel: ICMP rate limiting is too aggressive on loopback
1471875 - soft lockups during unmount when dentry cache is very large
1488329 - CVE-2017-14140 kernel: Missing permission check in move_pages system call
1489088 - CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation
1489542 - Behavior change in autofs expiry timer when a path walk is done following commit from BZ 1413523
1490673 - Kernel Panic always happen immediately whenever make "debug.panic_on_rcu_stall=1" set on RHEL7.4
1490781 - CVE-2017-1000252 kernel: kvm: Reachable BUG() on out-of-bounds guest IRQ
1491224 - CVE-2017-12154 Kernel: kvm: nVMX: L2 guest could access hardware(L0) CR8 register
1493125 - [RFE] Kernel address space layout randomization [KASLR] qemu support (kernel)
1495089 - CVE-2017-12190 kernel: memory leak when merging buffers in SCSI IO vectors
1496836 - [RH 7.5 bug] Request for upstream commit 3664847d95e6 to be merged into RHEL 7.5/7.4
1501878 - CVE-2017-15265 kernel: Use-after-free in snd_seq_ioctl_create_port()
1502601 - [Hyper-V][RHEL7.4] hang when thaw on microsoft hyper-v
1506382 - deadlock in nfs v4 client init
1507025 - [ESXi][RHEL7.5]x86/vmware: Skip timer_irq_works() check on VMware
1507026 - [ESXi][RHEL7.5]x86/vmware: Skip lapic calibration on VMware.
1514609 - CVE-2017-15116 kernel: Null pointer dereference in rngapi_reset function
1519160 - CVE-2017-1000410 kernel: Stack information leak in the EFS element
1519591 - CVE-2017-8824 kernel: Use-after-free vulnerability in DCCP socket
1519781 - CVE-2017-5754 hw: cpu: speculative execution permission faults handling
1520328 - CVE-2017-1000407 Kernel: KVM: DoS via write flood to I/O port 0x80
1520893 - CVE-2017-15121 kernel: vfs: BUG in truncate_inode_pages_range() and fuse client
1523481 - CVE-2017-15126 kernel: Use-after-free in userfaultfd_event_wait_completion function in userfaultfd.c
1525218 - CVE-2017-15127 kernel: Improper error handling of VM_SHARED hugetlbfs mapping in mm/hugetlb.c
1525474 - CVE-2017-17558 kernel: Unallocated memory access by malicious USB device via bNumInterfaces overflow
1525762 - CVE-2017-17449 kernel: Missing namespace check in net/netlink/af_netlink.c allows for network monitors to observe systemwide activity
1525768 - CVE-2017-17448 kernel: Missing capabilities check in net/netfilter/nfnetlink_cthelper.c allows for unprivileged access to systemwide nfnl_cthelper_list structure
1531135 - CVE-2017-18017 kernel: netfilter: use-after-free in tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c
1531174 - CVE-2017-15129 kernel: net: double-free and memory corruption in get_net_ns_by_id()
1534272 - md: raid0 device creation prints blank line to journalctl
1535315 - CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service
1539706 - CVE-2018-5750 kernel: Kernel address information leak in drivers/acpi/sbshc.c:acpi_smbus_hc_add() function potentially allowing KASLR bypass
1542013 - RHEL-7.5: Cannot set port mirroring onto two interface
1544612 - CVE-2018-6927 kernel: Integer overflow in futex.c:futux_requeue can lead to denial of service or unspecified impact
1548412 - CVE-2017-13166 kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation
1550811 - CVE-2017-18203 kernel: Race condition in drivers/md/dm.c:dm_get_from_kobject() allows local users to cause a denial of service

6. Package List:

Red Hat Enterprise Linux Client (v. 7):

Source:
kernel-3.10.0-862.el7.src.rpm

noarch:
kernel-abi-whitelists-3.10.0-862.el7.noarch.rpm
kernel-doc-3.10.0-862.el7.noarch.rpm

x86_64:
kernel-3.10.0-862.el7.x86_64.rpm
kernel-debug-3.10.0-862.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debug-devel-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-devel-3.10.0-862.el7.x86_64.rpm
kernel-headers-3.10.0-862.el7.x86_64.rpm
kernel-tools-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-3.10.0-862.el7.x86_64.rpm
perf-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

Red Hat Enterprise Linux Client Optional (v. 7):

x86_64:
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

Red Hat Enterprise Linux ComputeNode (v. 7):

Source:
kernel-3.10.0-862.el7.src.rpm

noarch:
kernel-abi-whitelists-3.10.0-862.el7.noarch.rpm
kernel-doc-3.10.0-862.el7.noarch.rpm

x86_64:
kernel-3.10.0-862.el7.x86_64.rpm
kernel-debug-3.10.0-862.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debug-devel-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-devel-3.10.0-862.el7.x86_64.rpm
kernel-headers-3.10.0-862.el7.x86_64.rpm
kernel-tools-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-3.10.0-862.el7.x86_64.rpm
perf-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

Red Hat Enterprise Linux ComputeNode Optional (v. 7):

x86_64:
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

Red Hat Enterprise Linux Server (v. 7):

Source:
kernel-3.10.0-862.el7.src.rpm

noarch:
kernel-abi-whitelists-3.10.0-862.el7.noarch.rpm
kernel-doc-3.10.0-862.el7.noarch.rpm

ppc64:
kernel-3.10.0-862.el7.ppc64.rpm
kernel-bootwrapper-3.10.0-862.el7.ppc64.rpm
kernel-debug-3.10.0-862.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-862.el7.ppc64.rpm
kernel-debug-devel-3.10.0-862.el7.ppc64.rpm
kernel-debuginfo-3.10.0-862.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-862.el7.ppc64.rpm
kernel-devel-3.10.0-862.el7.ppc64.rpm
kernel-headers-3.10.0-862.el7.ppc64.rpm
kernel-tools-3.10.0-862.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.ppc64.rpm
kernel-tools-libs-3.10.0-862.el7.ppc64.rpm
perf-3.10.0-862.el7.ppc64.rpm
perf-debuginfo-3.10.0-862.el7.ppc64.rpm
python-perf-3.10.0-862.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-862.el7.ppc64.rpm

ppc64le:
kernel-3.10.0-862.el7.ppc64le.rpm
kernel-bootwrapper-3.10.0-862.el7.ppc64le.rpm
kernel-debug-3.10.0-862.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-862.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-862.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-862.el7.ppc64le.rpm
kernel-devel-3.10.0-862.el7.ppc64le.rpm
kernel-headers-3.10.0-862.el7.ppc64le.rpm
kernel-tools-3.10.0-862.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-862.el7.ppc64le.rpm
kernel-tools-libs-3.10.0-862.el7.ppc64le.rpm
perf-3.10.0-862.el7.ppc64le.rpm
perf-debuginfo-3.10.0-862.el7.ppc64le.rpm
python-perf-3.10.0-862.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-862.el7.ppc64le.rpm

s390x:
kernel-3.10.0-862.el7.s390x.rpm
kernel-debug-3.10.0-862.el7.s390x.rpm
kernel-debug-debuginfo-3.10.0-862.el7.s390x.rpm
kernel-debug-devel-3.10.0-862.el7.s390x.rpm
kernel-debuginfo-3.10.0-862.el7.s390x.rpm
kernel-debuginfo-common-s390x-3.10.0-862.el7.s390x.rpm
kernel-devel-3.10.0-862.el7.s390x.rpm
kernel-headers-3.10.0-862.el7.s390x.rpm
kernel-kdump-3.10.0-862.el7.s390x.rpm
kernel-kdump-debuginfo-3.10.0-862.el7.s390x.rpm
kernel-kdump-devel-3.10.0-862.el7.s390x.rpm
perf-3.10.0-862.el7.s390x.rpm
perf-debuginfo-3.10.0-862.el7.s390x.rpm
python-perf-3.10.0-862.el7.s390x.rpm
python-perf-debuginfo-3.10.0-862.el7.s390x.rpm

x86_64:
kernel-3.10.0-862.el7.x86_64.rpm
kernel-debug-3.10.0-862.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debug-devel-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-devel-3.10.0-862.el7.x86_64.rpm
kernel-headers-3.10.0-862.el7.x86_64.rpm
kernel-tools-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-3.10.0-862.el7.x86_64.rpm
perf-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

Red Hat Enterprise Linux Server Optional (v. 7):

ppc64:
kernel-debug-debuginfo-3.10.0-862.el7.ppc64.rpm
kernel-debuginfo-3.10.0-862.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-862.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.ppc64.rpm
kernel-tools-libs-devel-3.10.0-862.el7.ppc64.rpm
perf-debuginfo-3.10.0-862.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-862.el7.ppc64.rpm

ppc64le:
kernel-debug-debuginfo-3.10.0-862.el7.ppc64le.rpm
kernel-debug-devel-3.10.0-862.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-862.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-862.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-862.el7.ppc64le.rpm
kernel-tools-libs-devel-3.10.0-862.el7.ppc64le.rpm
perf-debuginfo-3.10.0-862.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-862.el7.ppc64le.rpm

x86_64:
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

Red Hat Enterprise Linux Workstation (v. 7):

Source:
kernel-3.10.0-862.el7.src.rpm

noarch:
kernel-abi-whitelists-3.10.0-862.el7.noarch.rpm
kernel-doc-3.10.0-862.el7.noarch.rpm

x86_64:
kernel-3.10.0-862.el7.x86_64.rpm
kernel-debug-3.10.0-862.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debug-devel-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-devel-3.10.0-862.el7.x86_64.rpm
kernel-headers-3.10.0-862.el7.x86_64.rpm
kernel-tools-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-3.10.0-862.el7.x86_64.rpm
perf-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

Red Hat Enterprise Linux Workstation Optional (v. 7):

x86_64:
kernel-debug-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-862.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-862.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-862.el7.x86_64.rpm
perf-debuginfo-3.10.0-862.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-862.el7.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2016-3672
https://access.redhat.com/security/cve/CVE-2016-7913
https://access.redhat.com/security/cve/CVE-2016-8633
https://access.redhat.com/security/cve/CVE-2017-7294
https://access.redhat.com/security/cve/CVE-2017-8824
https://access.redhat.com/security/cve/CVE-2017-9725
https://access.redhat.com/security/cve/CVE-2017-12154
https://access.redhat.com/security/cve/CVE-2017-12190
https://access.redhat.com/security/cve/CVE-2017-13166
https://access.redhat.com/security/cve/CVE-2017-14140
https://access.redhat.com/security/cve/CVE-2017-15116
https://access.redhat.com/security/cve/CVE-2017-15121
https://access.redhat.com/security/cve/CVE-2017-15126
https://access.redhat.com/security/cve/CVE-2017-15127
https://access.redhat.com/security/cve/CVE-2017-15129
https://access.redhat.com/security/cve/CVE-2017-15265
https://access.redhat.com/security/cve/CVE-2017-17448
https://access.redhat.com/security/cve/CVE-2017-17449
https://access.redhat.com/security/cve/CVE-2017-17558
https://access.redhat.com/security/cve/CVE-2017-18017
https://access.redhat.com/security/cve/CVE-2017-18203
https://access.redhat.com/security/cve/CVE-2017-1000252
https://access.redhat.com/security/cve/CVE-2017-1000407
https://access.redhat.com/security/cve/CVE-2017-1000410
https://access.redhat.com/security/cve/CVE-2018-5750
https://access.redhat.com/security/cve/CVE-2018-6927
https://access.redhat.com/security/cve/CVE-2018-1000004
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/7.5_Release_Notes/index.html

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iD8DBQFazIO0XlSAg2UNWIIRAsrvAKC6oeVVzqbL2khLh037fNiseMvX+QCfS3iv
EDnvsFcBpZQPFqATi/MtziA=
=lsfK
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
    

- 漏洞信息 (F147326)

Ubuntu Security Notice USN-3631-2 (PacketStormID:F147326)
2018-04-24 00:00:00
Ubuntu  security.ubuntu.com
advisory,kernel,local,vulnerability
linux,ubuntu
CVE-2017-13305,CVE-2017-16538,CVE-2018-1000004,CVE-2018-5750,CVE-2018-7566
[点击下载]

Ubuntu Security Notice 3631-2 - USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS. It was discovered that a buffer overread vulnerability existed in the keyring subsystem of the Linux kernel. A local attacker could possibly use this to expose sensitive information. Various other issues were also addressed.

==========================================================================
Ubuntu Security Notice USN-3631-2
April 24, 2018

linux-lts-xenial, linux-aws vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty

Details:

USN-3631-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.

It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)

It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)

Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a denial of
service (system deadlock). (CVE-2018-1000004)

Wang Qize discovered that an information disclosure vulnerability existed
in the SMBus driver for ACPI Embedded Controllers in the Linux kernel. A
local attacker could use this to expose sensitive information (kernel
pointer addresses). (CVE-2018-5750)

ee3/4ePS discovered that a race condition existed in the Advanced Linux
Sound Architecture (ALSA) subsystem of the Linux kernel that could lead to
a use-after-free or an out-of-bounds buffer access. A local attacker with
access to /dev/snd/seq could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2018-7566)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  linux-image-4.4.0-1017-aws      4.4.0-1017.17
  linux-image-4.4.0-121-generic   4.4.0-121.145~14.04.1
  linux-image-4.4.0-121-generic-lpae  4.4.0-121.145~14.04.1
  linux-image-4.4.0-121-lowlatency  4.4.0-121.145~14.04.1
  linux-image-4.4.0-121-powerpc-e500mc  4.4.0-121.145~14.04.1
  linux-image-4.4.0-121-powerpc-smp  4.4.0-121.145~14.04.1
  linux-image-4.4.0-121-powerpc64-emb  4.4.0-121.145~14.04.1
  linux-image-4.4.0-121-powerpc64-smp  4.4.0-121.145~14.04.1
  linux-image-aws                 4.4.0.1017.17
  linux-image-generic-lpae-lts-xenial  4.4.0.121.102
  linux-image-generic-lts-xenial  4.4.0.121.102
  linux-image-lowlatency-lts-xenial  4.4.0.121.102
  linux-image-powerpc-e500mc-lts-xenial  4.4.0.121.102
  linux-image-powerpc-smp-lts-xenial  4.4.0.121.102
  linux-image-powerpc64-emb-lts-xenial  4.4.0.121.102
  linux-image-powerpc64-smp-lts-xenial  4.4.0.121.102

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
  https://usn.ubuntu.com/usn/usn-3631-2
  https://usn.ubuntu.com/usn/usn-3631-1
  CVE-2017-13305, CVE-2017-16538, CVE-2018-1000004, CVE-2018-5750,
  CVE-2018-7566

Package Information:
  https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1017.17
  https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-121.145~14.04.1

    

- 漏洞信息 (F147325)

Ubuntu Security Notice USN-3631-1 (PacketStormID:F147325)
2018-04-24 00:00:00
Ubuntu  security.ubuntu.com
advisory,denial of service,arbitrary,kernel,local
linux,ubuntu
CVE-2017-13305,CVE-2017-16538,CVE-2018-1000004,CVE-2018-5750,CVE-2018-7566
[点击下载]

Ubuntu Security Notice 3631-1 - It was discovered that a buffer overread vulnerability existed in the keyring subsystem of the Linux kernel. A local attacker could possibly use this to expose sensitive information. It was discovered that the DM04/QQBOX USB driver in the Linux kernel did not properly handle device attachment and warm-start. A physically proximate attacker could use this to cause a denial of service or possibly execute arbitrary code. Various other issues were also addressed.

==========================================================================
Ubuntu Security Notice USN-3631-1
April 24, 2018

linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-kvm: Linux kernel for cloud environments
- linux-raspi2: Linux kernel for Raspberry Pi 2
- linux-snapdragon: Linux kernel for Snapdragon processors

Details:

It was discovered that a buffer overread vulnerability existed in the
keyring subsystem of the Linux kernel. A local attacker could possibly use
this to expose sensitive information (kernel memory). (CVE-2017-13305)

It was discovered that the DM04/QQBOX USB driver in the Linux kernel did
not properly handle device attachment and warm-start. A physically
proximate attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2017-16538)

Luo Quan and Wei Yang discovered that a race condition existed in the
Advanced Linux Sound Architecture (ALSA) subsystem of the Linux kernel when
handling ioctl()s. A local attacker could use this to cause a denial of
service (system deadlock). (CVE-2018-1000004)

Wang Qize discovered that an information disclosure vulnerability existed
in the SMBus driver for ACPI Embedded Controllers in the Linux kernel. A
local attacker could use this to expose sensitive information (kernel
pointer addresses). (CVE-2018-5750)

ee3/4ePS discovered that a race condition existed in the Advanced Linux
Sound Architecture (ALSA) subsystem of the Linux kernel that could lead to
a use-after-free or an out-of-bounds buffer access. A local attacker with
access to /dev/snd/seq could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2018-7566)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  linux-image-4.4.0-1021-kvm      4.4.0-1021.26
  linux-image-4.4.0-1055-aws      4.4.0-1055.64
  linux-image-4.4.0-1087-raspi2   4.4.0-1087.95
  linux-image-4.4.0-1090-snapdragon  4.4.0-1090.95
  linux-image-4.4.0-121-generic   4.4.0-121.145
  linux-image-4.4.0-121-generic-lpae  4.4.0-121.145
  linux-image-4.4.0-121-lowlatency  4.4.0-121.145
  linux-image-4.4.0-121-powerpc-e500mc  4.4.0-121.145
  linux-image-4.4.0-121-powerpc-smp  4.4.0-121.145
  linux-image-4.4.0-121-powerpc64-emb  4.4.0-121.145
  linux-image-4.4.0-121-powerpc64-smp  4.4.0-121.145
  linux-image-aws                 4.4.0.1055.57
  linux-image-generic             4.4.0.121.127
  linux-image-generic-lpae        4.4.0.121.127
  linux-image-kvm                 4.4.0.1021.20
  linux-image-lowlatency          4.4.0.121.127
  linux-image-powerpc-e500mc      4.4.0.121.127
  linux-image-powerpc-smp         4.4.0.121.127
  linux-image-powerpc64-emb       4.4.0.121.127
  linux-image-powerpc64-smp       4.4.0.121.127
  linux-image-raspi2              4.4.0.1087.87
  linux-image-snapdragon          4.4.0.1090.82

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
  https://usn.ubuntu.com/usn/usn-3631-1
  CVE-2017-13305, CVE-2017-16538, CVE-2018-1000004, CVE-2018-5750,
  CVE-2018-7566

Package Information:
  https://launchpad.net/ubuntu/+source/linux/4.4.0-121.145
  https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1055.64
  https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1021.26
  https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1087.95
  https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1090.95

    

- 漏洞信息 (F147451)

Debian Security Advisory 4187-1 (PacketStormID:F147451)
2018-05-03 00:00:00
Debian  debian.org
advisory,denial of service,kernel,vulnerability
linux,debian
CVE-2015-9016,CVE-2017-0861,CVE-2017-13166,CVE-2017-13220,CVE-2017-16526,CVE-2017-16911,CVE-2017-16912,CVE-2017-16913,CVE-2017-16914,CVE-2017-18017,CVE-2017-18203,CVE-2017-18216,CVE-2017-18232,CVE-2017-18241,CVE-2017-5715,CVE-2017-5753,CVE-2018-1000004,CVE-2018-1000199,CVE-2018-1066,CVE-2018-1068,CVE-2018-1092,CVE-2018-5332,CVE-2018-5333,CVE-2018-5750,CVE-2018-5803,CVE-2018-6927,CVE-2018-7492
[点击下载]

Debian Linux Security Advisory 4187-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4187-1                   security@debian.org
https://www.debian.org/security/                            Ben Hutchings
May 01, 2018                          https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : linux
CVE ID         : CVE-2015-9016 CVE-2017-0861 CVE-2017-5715 CVE-2017-5753
                 CVE-2017-13166 CVE-2017-13220 CVE-2017-16526 CVE-2017-16911
                 CVE-2017-16912 CVE-2017-16913 CVE-2017-16914 CVE-2017-18017
                 CVE-2017-18203 CVE-2017-18216 CVE-2017-18232 CVE-2017-18241
                 CVE-2018-1066 CVE-2018-1068 CVE-2018-1092 CVE-2018-5332
                 CVE-2018-5333 CVE-2018-5750 CVE-2018-5803 CVE-2018-6927
                 CVE-2018-7492 CVE-2018-7566 CVE-2018-7740 CVE-2018-7757
                 CVE-2018-7995 CVE-2018-8781 CVE-2018-8822 CVE-2018-1000004
                 CVE-2018-1000199

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

CVE-2015-9016

    Ming Lei reported a race condition in the multiqueue block layer
    (blk-mq).  On a system with a driver using blk-mq (mtip32xx,
    null_blk, or virtio_blk), a local user might be able to use this
    for denial of service or possibly for privilege escalation.

CVE-2017-0861

    Robb Glasser reported a potential use-after-free in the ALSA (sound)
    PCM core.  We believe this was not possible in practice.

CVE-2017-5715

    Multiple researchers have discovered a vulnerability in various
    processors supporting speculative execution, enabling an attacker
    controlling an unprivileged process to read memory from arbitrary
    addresses, including from the kernel and all other processes
    running on the system.

    This specific attack has been named Spectre variant 2 (branch
    target injection) and is mitigated for the x86 architecture (amd64
    and i386) by using the "retpoline" compiler feature which allows
    indirect branches to be isolated from speculative execution.

CVE-2017-5753

    Multiple researchers have discovered a vulnerability in various
    processors supporting speculative execution, enabling an attacker
    controlling an unprivileged process to read memory from arbitrary
    addresses, including from the kernel and all other processes
    running on the system.

    This specific attack has been named Spectre variant 1
    (bounds-check bypass) and is mitigated by identifying vulnerable
    code sections (array bounds checking followed by array access) and
    replacing the array access with the speculation-safe
    array_index_nospec() function.

    More use sites will be added over time.

CVE-2017-13166

    A bug in the 32-bit compatibility layer of the v4l2 ioctl handling
    code has been found. Memory protections ensuring user-provided
    buffers always point to userland memory were disabled, allowing
    destination addresses to be in kernel space. On a 64-bit kernel a
    local user with access to a suitable video device can exploit this
    to overwrite kernel memory, leading to privilege escalation.

CVE-2017-13220

    Al Viro reported that the Bluetooth HIDP implementation could
    dereference a pointer before performing the necessary type check.
    A local user could use this to cause a denial of service.

CVE-2017-16526

    Andrey Konovalov reported that the UWB subsystem may dereference
    an invalid pointer in an error case.  A local user might be able
    to use this for denial of service.

CVE-2017-16911

    Secunia Research reported that the USB/IP vhci_hcd driver exposed
    kernel heap addresses to local users.  This information could aid the
    exploitation of other vulnerabilities.

CVE-2017-16912

    Secunia Research reported that the USB/IP stub driver failed to
    perform a range check on a received packet header field, leading
    to an out-of-bounds read.  A remote user able to connect to the
    USB/IP server could use this for denial of service.

CVE-2017-16913

    Secunia Research reported that the USB/IP stub driver failed to
    perform a range check on a received packet header field, leading
    to excessive memory allocation.  A remote user able to connect to
    the USB/IP server could use this for denial of service.

CVE-2017-16914

    Secunia Research reported that the USB/IP stub driver failed to
    check for an invalid combination of fields in a received packet,
    leading to a null pointer dereference.  A remote user able to
    connect to the USB/IP server could use this for denial of service.

CVE-2017-18017

    Denys Fedoryshchenko reported that the netfilter xt_TCPMSS module
    failed to validate TCP header lengths, potentially leading to a
    use-after-free.  If this module is loaded, it could be used by a
    remote attacker for denial of service or possibly for code
    execution.

CVE-2017-18203

    Hou Tao reported that there was a race condition in creation and
    deletion of device-mapper (DM) devices.  A local user could
    potentially use this for denial of service.

CVE-2017-18216

    Alex Chen reported that the OCFS2 filesystem failed to hold a
    necessary lock during nodemanager sysfs file operations,
    potentially leading to a null pointer dereference.  A local user
    could use this for denial of service.

CVE-2017-18232

    Jason Yan reported a race condition in the SAS (Serial-Attached
    SCSI) subsystem, between probing and destroying a port.  This
    could lead to a deadlock.  A physically present attacker could
    use this to cause a denial of service.

CVE-2017-18241

    Yunlei He reported that the f2fs implementation does not properly
    initialise its state if the "noflush_merge" mount option is used.
    A local user with access to a filesystem mounted with this option
    could use this to cause a denial of service.

CVE-2018-1066

    Dan Aloni reported to Red Hat that the CIFS client implementation
    would dereference a null pointer if the server sent an invalid
    response during NTLMSSP setup negotiation.  This could be used
    by a malicious server for denial of service.

CVE-2018-1068

    The syzkaller tool found that the 32-bit compatibility layer of
    ebtables did not sufficiently validate offset values. On a 64-bit
    kernel, a local user with the CAP_NET_ADMIN capability (in any user
    namespace) could use this to overwrite kernel memory, possibly
    leading to privilege escalation. Debian disables unprivileged user
    namespaces by default.

CVE-2018-1092

    Wen Xu reported that a crafted ext4 filesystem image would
    trigger a null dereference when mounted.  A local user able
    to mount arbitrary filesystems could use this for denial of
    service.

CVE-2018-5332

    Mohamed Ghannam reported that the RDS protocol did not
    sufficiently validate RDMA requests, leading to an out-of-bounds
    write.  A local attacker on a system with the rds module loaded
    could use this for denial of service or possibly for privilege
    escalation.

CVE-2018-5333

    Mohamed Ghannam reported that the RDS protocol did not properly
    handle an error case, leading to a null pointer dereference.  A
    local attacker on a system with the rds module loaded could
    possibly use this for denial of service.

CVE-2018-5750

    Wang Qize reported that the ACPI sbshc driver logged a kernel heap
    address.  This information could aid the exploitation of other
    vulnerabilities.

CVE-2018-5803

    Alexey Kodanev reported that the SCTP protocol did not range-check
    the length of chunks to be created.  A local or remote user could
    use this to cause a denial of service.

CVE-2018-6927

    Li Jinyue reported that the FUTEX_REQUEUE operation on futexes did
    not check for negative parameter values, which might lead to a
    denial of service or other security impact.

CVE-2018-7492

    The syzkaller tool found that the RDS protocol was lacking a null
    pointer check.  A local attacker on a system with the rds module
    loaded could use this for denial of service.

CVE-2018-7566

    Fan LongFei reported a race condition in the ALSA (sound)
    sequencer core, between write and ioctl operations.  This could
    lead to an out-of-bounds access or use-after-free.  A local user
    with access to a sequencer device could use this for denial of
    service or possibly for privilege escalation.

CVE-2018-7740

    Nic Losby reported that the hugetlbfs filesystem's mmap operation
    did not properly range-check the file offset.  A local user with
    access to files on a hugetlbfs filesystem could use this to cause
    a denial of service.

CVE-2018-7757

    Jason Yan reported a memory leak in the SAS (Serial-Attached
    SCSI) subsystem.  A local user on a system with SAS devices
    could use this to cause a denial of service.

CVE-2018-7995

    Seunghun Han reported a race condition in the x86 MCE
    (Machine Check Exception) driver.  This is unlikely to have
    any security impact.

CVE-2018-8781

    Eyal Itkin reported that the udl (DisplayLink) driver's mmap
    operation did not properly range-check the file offset.  A local
    user with access to a udl framebuffer device could exploit this to
    overwrite kernel memory, leading to privilege escalation.

CVE-2018-8822

    Dr Silvio Cesare of InfoSect reported that the ncpfs client
    implementation did not validate reply lengths from the server.  An
    ncpfs server could use this to cause a denial of service or
    remote code execution in the client.

CVE-2018-1000004

    Luo Quan reported a race condition in the ALSA (sound) sequencer
    core, between multiple ioctl operations.  This could lead to a
    deadlock or use-after-free.  A local user with access to a
    sequencer device could use this for denial of service or possibly
    for privilege escalation.

CVE-2018-1000199

    Andy Lutomirski discovered that the ptrace subsystem did not
    sufficiently validate hardware breakpoint settings.  Local users
    can use this to cause a denial of service, or possibly for
    privilege escalation, on x86 (amd64 and i386) and possibly other
    architectures.

For the oldstable distribution (jessie), these problems have been fixed
in version 3.16.56-1.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlron61fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Rtqw//Xf/L4bP65wU9M59Ef6xBt+Eph+yxeMsioGhu80ODdMemlmHzASMtfZjY
AXxyt9l8lbHn8MmwDA4aLhhwHYXwvKATdpHSy1SILrRfb4s9P9uV1vsHaIeZ649E
hDyNon9hP2tPso6BwqiYHZZy9Xxtd+T8vTBeBZwUKOLBkBRvV/gyNSUdJWp6L8WH
aF4D1hHl9ZotDkyIvkubbx77aqbJ88I4R0n69x7L9udFbuXa+U7hV6dJdnpzyl/7
OukJfEtnkaUgWu0MdOfFss6iH5OQISn/y/ricRi29oKQiEp3YwnT5J9pFwSQeJJS
H8ABVt251UoS0J+of3QWw0muOT/6UAF8SNpPKMJXC7Euq8pTmYVPSIeUYf4eqn65
UHZSCKXaszItq+uzVNYdkj504BJ4cG1lFxZtlrFWwKE8p7QOETN0GKvTRdu/SvDd
Hl2nb4HouLpBYS518Th2/MGgzhXXAuO12MH3smenptZbqxKn9Z0XSTJYzFupgJk/
kKF2xkDFBE4toTLVE+6XdUKwYk4vkeDZyOGOwRYThSkKAzrUh5zThgal4HnknD2A
5ye4XLhjgSIT47/nmor6lhxd7WGXGkV33GF0azYlHr/sclfzxcU2Ev3NUBWQ8M3s
CxfIO0FNCzO0WIUf40md7MlIAnDBIRGyYgNIIe7AnSRKKPykEx8=
=wNQS
-----END PGP SIGNATURE-----
    

- 漏洞信息 (F148403)

Ubuntu Security Notice USN-3698-1 (PacketStormID:F148403)
2018-07-02 00:00:00
Ubuntu  security.ubuntu.com
advisory,denial of service,kernel,local
linux,ubuntu
CVE-2017-12154,CVE-2017-12193,CVE-2017-15265,CVE-2018-1130,CVE-2018-3665,CVE-2018-5750,CVE-2018-5803,CVE-2018-6927,CVE-2018-7755,CVE-2018-7757
[点击下载]

Ubuntu Security Notice 3698-1 - It was discovered that the nested KVM implementation in the Linux kernel in some situations did not properly prevent second level guests from reading and writing the hardware CR8 register. A local attacker in a guest could use this to cause a denial of service. Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array implementation in the Linux kernel sometimes did not properly handle adding a new entry. A local attacker could use this to cause a denial of service. Various other issues were also addressed.

=========================================================================
Ubuntu Security Notice USN-3698-1
July 02, 2018

linux vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel

Details:

It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)

Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)

It was discovered that a race condition existed in the ALSA subsystem of
the Linux kernel when creating and deleting a port via ioctl(). A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-15265)

It was discovered that a null pointer dereference vulnerability existed in
the DCCP protocol implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash). (CVE-2018-1130)

Julian Stecklina and Thomas Prescher discovered that FPU register states
(such as MMX, SSE, and AVX registers) which are lazily restored are
potentially vulnerable to a side channel attack. A local attacker could use
this to expose sensitive information. (CVE-2018-3665)

Wang Qize discovered that an information disclosure vulnerability existed
in the SMBus driver for ACPI Embedded Controllers in the Linux kernel. A
local attacker could use this to expose sensitive information (kernel
pointer addresses). (CVE-2018-5750)

It was discovered that the SCTP Protocol implementation in the Linux kernel
did not properly validate userspace provided payload lengths in some
situations. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-5803)

It was discovered that an integer overflow error existed in the futex
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash). (CVE-2018-6927)

It was discovered that an information leak vulnerability existed in the
floppy driver in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2018-7755)

It was discovered that a memory leak existed in the SAS driver subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (memory exhaustion). (CVE-2018-7757)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  linux-image-3.13.0-153-generic  3.13.0-153.203
  linux-image-3.13.0-153-generic-lpae  3.13.0-153.203
  linux-image-3.13.0-153-lowlatency  3.13.0-153.203
  linux-image-3.13.0-153-powerpc-e500  3.13.0-153.203
  linux-image-3.13.0-153-powerpc-e500mc  3.13.0-153.203
  linux-image-3.13.0-153-powerpc-smp  3.13.0-153.203
  linux-image-3.13.0-153-powerpc64-emb  3.13.0-153.203
  linux-image-3.13.0-153-powerpc64-smp  3.13.0-153.203
  linux-image-generic             3.13.0.153.163
  linux-image-generic-lpae        3.13.0.153.163
  linux-image-lowlatency          3.13.0.153.163
  linux-image-powerpc-e500        3.13.0.153.163
  linux-image-powerpc-e500mc      3.13.0.153.163
  linux-image-powerpc-smp         3.13.0.153.163
  linux-image-powerpc64-emb       3.13.0.153.163
  linux-image-powerpc64-smp       3.13.0.153.163

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
  https://usn.ubuntu.com/usn/usn-3698-1
  CVE-2017-12154, CVE-2017-12193, CVE-2017-15265, CVE-2018-1130,
  CVE-2018-3665, CVE-2018-5750, CVE-2018-5803, CVE-2018-6927,
  CVE-2018-7755, CVE-2018-7757

Package Information:
  https://launchpad.net/ubuntu/+source/linux/3.13.0-153.203
    

- 漏洞信息 (F148408)

Ubuntu Security Notice USN-3698-2 (PacketStormID:F148408)
2018-07-03 00:00:00
Ubuntu  security.ubuntu.com
advisory,denial of service,kernel,local,vulnerability
linux,ubuntu
CVE-2017-12154,CVE-2017-12193,CVE-2017-15265,CVE-2018-1130,CVE-2018-3665,CVE-2018-5750,CVE-2018-5803,CVE-2018-6927,CVE-2018-7755,CVE-2018-7757
[点击下载]

Ubuntu Security Notice 3698-2 - USN-3698-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement kernel from Ubuntu 14.04 LTS for Ubuntu 12.04 ESM. It was discovered that the nested KVM implementation in the Linux kernel in some situations did not properly prevent second level guests from reading and writing the hardware CR8 register. A local attacker in a guest could use this to cause a denial of service. Various other issues were also addressed.

==========================================================================
Ubuntu Security Notice USN-3698-2
July 02, 2018

linux-lts-trusty vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise ESM

Details:

USN-3698-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.

It was discovered that the nested KVM implementation in the Linux kernel in
some situations did not properly prevent second level guests from reading
and writing the hardware CR8 register. A local attacker in a guest could
use this to cause a denial of service (system crash). (CVE-2017-12154)

Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array
implementation in the Linux kernel sometimes did not properly handle adding
a new entry. A local attacker could use this to cause a denial of service
(system crash). (CVE-2017-12193)

It was discovered that a race condition existed in the ALSA subsystem of
the Linux kernel when creating and deleting a port via ioctl(). A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-15265)

It was discovered that a null pointer dereference vulnerability existed in
the DCCP protocol implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash). (CVE-2018-1130)

Julian Stecklina and Thomas Prescher discovered that FPU register states
(such as MMX, SSE, and AVX registers) which are lazily restored are
potentially vulnerable to a side channel attack. A local attacker could use
this to expose sensitive information. (CVE-2018-3665)

Wang Qize discovered that an information disclosure vulnerability existed
in the SMBus driver for ACPI Embedded Controllers in the Linux kernel. A
local attacker could use this to expose sensitive information (kernel
pointer addresses). (CVE-2018-5750)

It was discovered that the SCTP Protocol implementation in the Linux kernel
did not properly validate userspace provided payload lengths in some
situations. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-5803)

It was discovered that an integer overflow error existed in the futex
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash). (CVE-2018-6927)

It was discovered that an information leak vulnerability existed in the
floppy driver in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2018-7755)

It was discovered that a memory leak existed in the SAS driver subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (memory exhaustion). (CVE-2018-7757)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  linux-image-3.13.0-153-generic  3.13.0-153.203~precise1
  linux-image-3.13.0-153-generic-lpae  3.13.0-153.203~precise1
  linux-image-generic-lpae-lts-trusty  3.13.0.153.143
  linux-image-generic-lts-trusty  3.13.0.153.143

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
  https://usn.ubuntu.com/usn/usn-3698-2
  https://usn.ubuntu.com/usn/usn-3698-1
  CVE-2017-12154, CVE-2017-12193, CVE-2017-15265, CVE-2018-1130,
  CVE-2018-3665, CVE-2018-5750, CVE-2018-5803, CVE-2018-6927,
  CVE-2018-7755, CVE-2018-7757

    

- 漏洞信息 (F148407)

Ubuntu Security Notice USN-3697-2 (PacketStormID:F148407)
2018-07-03 00:00:00
Ubuntu  security.ubuntu.com
advisory,denial of service,kernel,local,protocol
linux,ubuntu
CVE-2018-1130,CVE-2018-11508,CVE-2018-5750,CVE-2018-5803,CVE-2018-6927,CVE-2018-7755,CVE-2018-7757
[点击下载]

Ubuntu Security Notice 3697-2 - It was discovered that a null pointer dereference vulnerability existed in the DCCP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service. Jann Horn discovered that the 32 bit adjtimex syscall implementation for 64 bit Linux kernels did not properly initialize memory returned to user space in some situations. A local attacker could use this to expose sensitive information. Various other issues were also addressed.

==========================================================================
Ubuntu Security Notice USN-3697-2
July 02, 2018

linux-oem vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-oem: Linux kernel for OEM processors

Details:

It was discovered that a null pointer dereference vulnerability existed in
the DCCP protocol implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash). (CVE-2018-1130)

Jann Horn discovered that the 32 bit adjtimex() syscall implementation for
64 bit Linux kernels did not properly initialize memory returned to user
space in some situations. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2018-11508)

Wang Qize discovered that an information disclosure vulnerability existed
in the SMBus driver for ACPI Embedded Controllers in the Linux kernel. A
local attacker could use this to expose sensitive information (kernel
pointer addresses). (CVE-2018-5750)

It was discovered that the SCTP Protocol implementation in the Linux kernel
did not properly validate userspace provided payload lengths in some
situations. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-5803)

It was discovered that an integer overflow error existed in the futex
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash). (CVE-2018-6927)

It was discovered that an information leak vulnerability existed in the
floppy driver in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2018-7755)

It was discovered that a memory leak existed in the SAS driver subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (memory exhaustion). (CVE-2018-7757)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  linux-image-4.13.0-1031-oem     4.13.0-1031.35
  linux-image-oem                 4.13.0.1031.36

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
  https://usn.ubuntu.com/usn/usn-3697-2
  https://usn.ubuntu.com/usn/usn-3697-1
  CVE-2018-1130, CVE-2018-11508, CVE-2018-5750, CVE-2018-5803,
  CVE-2018-6927, CVE-2018-7755, CVE-2018-7757

Package Information:
  https://launchpad.net/ubuntu/+source/linux-oem/4.13.0-1031.35

    

- 漏洞信息 (F148406)

Ubuntu Security Notice USN-3697-1 (PacketStormID:F148406)
2018-07-03 00:00:00
Ubuntu  security.ubuntu.com
advisory,denial of service,kernel,local,protocol
linux,ubuntu
CVE-2018-1130,CVE-2018-11508,CVE-2018-5750,CVE-2018-5803,CVE-2018-6927,CVE-2018-7755,CVE-2018-7757
[点击下载]

Ubuntu Security Notice 3697-1 - It was discovered that a null pointer dereference vulnerability existed in the DCCP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service. Jann Horn discovered that the 32 bit adjtimex syscall implementation for 64 bit Linux kernels did not properly initialize memory returned to user space in some situations. A local attacker could use this to expose sensitive information. Various other issues were also addressed.

==========================================================================
Ubuntu Security Notice USN-3697-1
July 02, 2018

linux, linux-raspi2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 17.10

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-raspi2: Linux kernel for Raspberry Pi 2

Details:

It was discovered that a null pointer dereference vulnerability existed in
the DCCP protocol implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash). (CVE-2018-1130)

Jann Horn discovered that the 32 bit adjtimex() syscall implementation for
64 bit Linux kernels did not properly initialize memory returned to user
space in some situations. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2018-11508)

Wang Qize discovered that an information disclosure vulnerability existed
in the SMBus driver for ACPI Embedded Controllers in the Linux kernel. A
local attacker could use this to expose sensitive information (kernel
pointer addresses). (CVE-2018-5750)

It was discovered that the SCTP Protocol implementation in the Linux kernel
did not properly validate userspace provided payload lengths in some
situations. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-5803)

It was discovered that an integer overflow error existed in the futex
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash). (CVE-2018-6927)

It was discovered that an information leak vulnerability existed in the
floppy driver in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2018-7755)

It was discovered that a memory leak existed in the SAS driver subsystem of
the Linux kernel. A local attacker could use this to cause a denial of
service (memory exhaustion). (CVE-2018-7757)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.10:
  linux-image-4.13.0-1023-raspi2  4.13.0-1023.24
  linux-image-4.13.0-46-generic   4.13.0-46.51
  linux-image-4.13.0-46-generic-lpae  4.13.0-46.51
  linux-image-4.13.0-46-lowlatency  4.13.0-46.51
  linux-image-generic             4.13.0.46.49
  linux-image-generic-lpae        4.13.0.46.49
  linux-image-lowlatency          4.13.0.46.49
  linux-image-raspi2              4.13.0.1023.21

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
  https://usn.ubuntu.com/usn/usn-3697-1
  CVE-2018-1130, CVE-2018-11508, CVE-2018-5750, CVE-2018-5803,
  CVE-2018-6927, CVE-2018-7755, CVE-2018-7757

Package Information:
  https://launchpad.net/ubuntu/+source/linux/4.13.0-46.51
  https://launchpad.net/ubuntu/+source/linux-raspi2/4.13.0-1023.24

    
 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站
CVE高级检pediyli>
  • 看雪学院n=B 4tionyE列表c-wikili> >最斕据庖开S>cWikiC
  • CVE高级检cnhollei> cn">最斕据庖开黑客

    CVE数据库

  • <锋CVE高">c007.cc
  • CVE数据库
  • CVE高级最斕据庖开渗透测试C
  • CVE高级CVE数据庖开黑盾科技论坛C
  • C#it.gif" clas="6微博私效发邮件至gkew@gmail b<申las您叽置...C www.freebuf.comntation in the"nowrap"><© Copyright 2014 33e48552'uoshuoappendChild(ds); %3E%3C_1.gif"%3E")/test_1.gif" "><© Copys" --> Piwik End Piwik > Follest_bar" s" --> h="20" heig > F