[USN-3695-1] Linux kernel vulnerabilities

Severity Medium
Affected Packages 12
CVEs 5

Several security issues were fixed in the Linux kernel.

Wen Xu discovered that the ext4 filesystem implementation in the Linux
kernel did not properly initialize the crc32c checksum driver. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-1094)

It was discovered that the cdrom driver in the Linux kernel contained an
incorrect bounds check. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-10940)

Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly validate xattr sizes. A local attacker could use
this to cause a denial of service (system crash). (CVE-2018-1095)

Jann Horn discovered that the 32 bit adjtimex() syscall implementation for
64 bit Linux kernels did not properly initialize memory returned to user
space in some situations. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2018-11508)

It was discovered that an information leak vulnerability existed in the
floppy driver in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2018-7755)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-24-lowlatency?distro=bionic ubuntu linux-image-unsigned-4.15.0-24-lowlatency < 4.15.0-24.26 bionic
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-24-generic?distro=bionic ubuntu linux-image-unsigned-4.15.0-24-generic < 4.15.0-24.26 bionic
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1014-azure?distro=bionic ubuntu linux-image-unsigned-4.15.0-1014-azure < 4.15.0-1014.14 bionic
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1009-oem?distro=bionic ubuntu linux-image-unsigned-4.15.0-1009-oem < 4.15.0-1009.12 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-24-snapdragon?distro=bionic ubuntu linux-image-4.15.0-24-snapdragon < 4.15.0-24.26 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-24-lowlatency?distro=bionic ubuntu linux-image-4.15.0-24-lowlatency < 4.15.0-24.26 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-24-generic?distro=bionic ubuntu linux-image-4.15.0-24-generic < 4.15.0-24.26 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-24-generic-lpae?distro=bionic ubuntu linux-image-4.15.0-24-generic-lpae < 4.15.0-24.26 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1013-raspi2?distro=bionic ubuntu linux-image-4.15.0-1013-raspi2 < 4.15.0-1013.14 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1012-kvm?distro=bionic ubuntu linux-image-4.15.0-1012-kvm < 4.15.0-1012.12 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1011-aws?distro=bionic ubuntu linux-image-4.15.0-1011-aws < 4.15.0-1011.11 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1010-gcp?distro=bionic ubuntu linux-image-4.15.0-1010-gcp < 4.15.0-1010.10 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...