[USN-3762-2] Linux kernel (HWE) vulnerabilities

Severity Low
Affected Packages 7
CVEs 2

Several security issues were fixed in the Linux kernel.

USN-3762-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.

It was discovered that the VirtIO subsystem in the Linux kernel did not
properly initialize memory in some situations. A local attacker could use
this to possibly expose sensitive information (kernel memory).
(CVE-2018-1118)

Seunghun Han discovered an information leak in the ACPI handling code in
the Linux kernel when handling early termination of ACPI table loading. A
local attacker could use this to expose sensitive informal (kernel address
locations). (CVE-2017-13695)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-34-lowlatency?distro=xenial ubuntu linux-image-unsigned-4.15.0-34-lowlatency < 4.15.0-34.37~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-34-generic?distro=xenial ubuntu linux-image-unsigned-4.15.0-34-generic < 4.15.0-34.37~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1023-azure?distro=xenial ubuntu linux-image-unsigned-4.15.0-1023-azure < 4.15.0-1023.24~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1019-gcp?distro=xenial ubuntu linux-image-unsigned-4.15.0-1019-gcp < 4.15.0-1019.20~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-34-lowlatency?distro=xenial ubuntu linux-image-4.15.0-34-lowlatency < 4.15.0-34.37~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-34-generic?distro=xenial ubuntu linux-image-4.15.0-34-generic < 4.15.0-34.37~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-34-generic-lpae?distro=xenial ubuntu linux-image-4.15.0-34-generic-lpae < 4.15.0-34.37~16.04.1 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...