Security updates for Ubuntu-zenial-lts-zesty

3 views
Skip to first unread message

Irina Semenova

unread,
Aug 2, 2018, 10:01:02 AM8/2/18
to kernelca...@googlegroups.com
To apply patches do the following: 

Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.

You can manually update the server by running:
# /usr/bin/kcarectl --update

CHANGELOG:
ubuntu-xenial-lts-zesty:
  CVE-2017-12146: The driver_override implementation in drivers/base/platform.c in
    the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging
    a race condition between a read operation and a store operation that involve different
    overrides.
  CVE-2017-16939: The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the
    Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial
    of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in
    conjunction with XFRM_MSG_GETPOLICY Netlink messages.
  CVE-2017-8824: The dccp_disconnect function in net/dccp/proto.c in the Linux kernel
    through 4.14.3 allows local users to gain privileges or cause a denial of service
    (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
  cvelist: [CVE-2017-8824, CVE-2017-12146, CVE-2017-16939]
  latest-version: 4.10.0-42.46~16.04.1

--
-- 
Regards, 
Irina Semenova | Project Coordinator of KernelCare 
Skype: iras535

CloudLinux.com  |  KernelCare.com  |  Imunify360 

helpdesk.cloudlinux.com: 24/7 Free, exceptionally good support
Follow twitter.com/CloudLinuxOS for technical updates
Reply all
Reply to author
Forward
0 new messages