[USN-3740-1] Linux kernel vulnerabilities

Severity High
Affected Packages 12
CVEs 3

Several security issues were fixed in the Linux kernel.

It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)

It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)

Juha-Matti Tilli discovered that the IP implementation in the Linux kernel
performed algorithmically expensive operations in some situations when
handling incoming packet fragments. A remote attacker could use this to
cause a denial of service. (CVE-2018-5391)

ID
USN-3740-1
Severity
high
URL
https://ubuntu.com/security/notices/USN-3740-1
Published
2018-08-14T21:47:54
(6 years ago)
Modified
2018-08-14T21:47:54
(6 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-32-lowlatency?distro=bionic ubuntu linux-image-unsigned-4.15.0-32-lowlatency < 4.15.0-32.35 bionic
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-32-generic?distro=bionic ubuntu linux-image-unsigned-4.15.0-32-generic < 4.15.0-32.35 bionic
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1021-azure?distro=bionic ubuntu linux-image-unsigned-4.15.0-1021-azure < 4.15.0-1021.21 bionic
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1015-oem?distro=bionic ubuntu linux-image-unsigned-4.15.0-1015-oem < 4.15.0-1015.18 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-32-snapdragon?distro=bionic ubuntu linux-image-4.15.0-32-snapdragon < 4.15.0-32.35 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-32-lowlatency?distro=bionic ubuntu linux-image-4.15.0-32-lowlatency < 4.15.0-32.35 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-32-generic?distro=bionic ubuntu linux-image-4.15.0-32-generic < 4.15.0-32.35 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-32-generic-lpae?distro=bionic ubuntu linux-image-4.15.0-32-generic-lpae < 4.15.0-32.35 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1020-raspi2?distro=bionic ubuntu linux-image-4.15.0-1020-raspi2 < 4.15.0-1020.22 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1019-kvm?distro=bionic ubuntu linux-image-4.15.0-1019-kvm < 4.15.0-1019.19 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1019-aws?distro=bionic ubuntu linux-image-4.15.0-1019-aws < 4.15.0-1019.19 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1017-gcp?distro=bionic ubuntu linux-image-4.15.0-1017-gcp < 4.15.0-1017.18 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...