[USN-4710-1] Linux kernel vulnerability

Severity Medium
Affected Packages 27
CVEs 1

The system could be made to crash under certain conditions.

Kiyin (尹亮) discovered that the perf subsystem in the Linux kernel did
not properly deallocate memory in some situations. A privileged attacker
could use this to cause a denial of service (kernel memory exhaustion).

Package Affected Version
pkg:deb/ubuntu/linux-image-virtual?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-oem?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-generic?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=xenial < 4.15.0.133.131
pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic < 4.15.0.135.122
pkg:deb/ubuntu/linux-image-4.15.0-135-lowlatency?distro=bionic < 4.15.0-135.139
pkg:deb/ubuntu/linux-image-4.15.0-135-generic?distro=bionic < 4.15.0-135.139
pkg:deb/ubuntu/linux-image-4.15.0-135-generic-lpae?distro=bionic < 4.15.0-135.139
pkg:deb/ubuntu/linux-image-4.15.0-133-lowlatency?distro=xenial < 4.15.0-133.137~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-133-generic?distro=xenial < 4.15.0-133.137~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-133-generic-lpae?distro=xenial < 4.15.0-133.137~16.04.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=bionic ubuntu linux-image-virtual < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=xenial ubuntu linux-image-virtual-hwe-16.04 < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic ubuntu linux-image-virtual-hwe-16.04 < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=xenial ubuntu linux-image-virtual-hwe-16.04-edge < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic ubuntu linux-image-virtual-hwe-16.04-edge < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-oem?distro=xenial ubuntu linux-image-oem < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic ubuntu linux-image-lowlatency < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=xenial ubuntu linux-image-lowlatency-hwe-16.04 < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04 < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=xenial ubuntu linux-image-lowlatency-hwe-16.04-edge < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04-edge < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-generic?distro=bionic ubuntu linux-image-generic < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic ubuntu linux-image-generic-lpae < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=xenial ubuntu linux-image-generic-lpae-hwe-16.04 < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04 < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=xenial ubuntu linux-image-generic-lpae-hwe-16.04-edge < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04-edge < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=xenial ubuntu linux-image-generic-hwe-16.04 < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic ubuntu linux-image-generic-hwe-16.04 < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=xenial ubuntu linux-image-generic-hwe-16.04-edge < 4.15.0.133.131 xenial
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-hwe-16.04-edge < 4.15.0.135.122 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-135-lowlatency?distro=bionic ubuntu linux-image-4.15.0-135-lowlatency < 4.15.0-135.139 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-135-generic?distro=bionic ubuntu linux-image-4.15.0-135-generic < 4.15.0-135.139 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-135-generic-lpae?distro=bionic ubuntu linux-image-4.15.0-135-generic-lpae < 4.15.0-135.139 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-133-lowlatency?distro=xenial ubuntu linux-image-4.15.0-133-lowlatency < 4.15.0-133.137~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-133-generic?distro=xenial ubuntu linux-image-4.15.0-133-generic < 4.15.0-133.137~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-133-generic-lpae?distro=xenial ubuntu linux-image-4.15.0-133-generic-lpae < 4.15.0-133.137~16.04.1 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...