TAGNAME: update-2019-01-28-2
ubuntu-xenial:
CVE-2018-10880: Linux kernel is vulnerable to a stack-out-of-bounds write in the
ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data().
An attacker could use this to cause a system crash and a denial of service.
CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the
Linux kernel through 4.17.3 has an integer overflow via a large relative timeout
because ktime_add_safe is not used.
CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. A denial of service (out-of-bounds memory access and BUG) can occur upon
encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c
when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc
control has not been initialized.
CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c
when opening a file (that is purportedly a hard link) in an hfs+ filesystem that
has malformed catalog data, and is mounted read-only without a metadata directory.
CVE-2018-17972: An issue was discovered in the proc_pid_stack function in fs/proc/base.c
in the Linux kernel through 4.18.11. It does not ensure that only root may inspect
the kernel stack of an arbitrary task, allowing a local attacker to exploit racy
stack unwinding and leak kernel task stack contents.
cvelist: [CVE-2018-10880, CVE-2018-13053, CVE-2018-13096, CVE-2018-14609, CVE-2018-14617,
CVE-2018-17972]
latest-version: 4.4.0-141.167
ubuntu-xenial-aws:
CVE-2018-10880: Linux kernel is vulnerable to a stack-out-of-bounds write in the
ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data().
An attacker could use this to cause a system crash and a denial of service.
CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the
Linux kernel through 4.17.3 has an integer overflow via a large relative timeout
because ktime_add_safe is not used.
CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. A denial of service (out-of-bounds memory access and BUG) can occur upon
encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c
when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc
control has not been initialized.
CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c
when opening a file (that is purportedly a hard link) in an hfs+ filesystem that
has malformed catalog data, and is mounted read-only without a metadata directory.
CVE-2018-17972: An issue was discovered in the proc_pid_stack function in fs/proc/base.c
in the Linux kernel through 4.18.11. It does not ensure that only root may inspect
the kernel stack of an arbitrary task, allowing a local attacker to exploit racy
stack unwinding and leak kernel task stack contents.
cvelist: [CVE-2018-10880, CVE-2018-13053, CVE-2018-13096, CVE-2018-14609, CVE-2018-14617,
CVE-2018-17972]
latest-version: 4.4.0-1074.84
ubuntu-xenial-lts-bionic:
CVE-2017-13168: It was discovered that the generic SCSI driver in the Linux kernel
did not properly enforce permissions on kernel memory access. A local attacker
could use this to expose sensitive information or possibly elevate privileges.
CVE-2017-13695: Seunghun Han discovered an information leak in the ACPI handling
code in the Linux kernel when handling early termination of ACPI table loading.
A local attacker could use this to expose sensitive informal (kernel addresslocations).
CVE-2018-1000200: It was discovered that, when attempting to handle an out-of-memory
situation, a null pointer dereference could be triggered in the Linux kernel in
some circumstances. A local attacker could use this to cause a denial of service
(system crash).
CVE-2018-1000204: It was discovered that an information leak existed in the generic
SCSI driver in the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory).
CVE-2018-10840: Wen Xu discovered that the XFS filesystem implementation in the
Linux kernel did not properly validate xattr information. An attacker could use
this to construct a malicious xfs image that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
CVE-2018-10876: Wen Xu discovered that a use-after-free vulnerability existed in
the ext4 filesystem implementation in the Linux kernel. An attacker could use
this to construct a malicious ext4 image that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
CVE-2018-10877: Wen Xu discovered that a buffer overflow existed in the ext4 filesystem
implementation in the Linux kernel. An attacker could use this to construct a
malicious ext4 image that, when mounted, could cause a denial of service (system
crash) or possibly execute arbitrary code.
CVE-2018-10878: Wen Xu discovered that an out-of-bounds write vulnerability existed
in the ext4 filesystem implementation in the Linux kernel. An attacker could use
this to construct a malicious ext4 image that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
CVE-2018-10879: Wen Xu discovered that a use-after-free vulnerability existed in
the ext4 filesystem implementation in the Linux kernel. An attacker could use
this to construct a malicious ext4 image that, when mounted, could cause a
CVE-2018-10881: Wen Xu discovered that the ext4 filesystem implementation in the
Linux kernel did not properly keep meta-data information consistent in some situations.
An attacker could use this to construct a malicious ext4 image that, when mounted,
could cause a denial of service (system crash).
CVE-2018-10882: Wen Xu discovered that an out-of-bounds write vulnerability existed
in the ext4 filesystem implementation in the Linux kernel. An attacker could use
this to construct a malicious ext4 image that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
CVE-2018-10902: It was discovered that a race condition existed in the raw MIDI
driver for the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibl execute
arbitrary code.
CVE-2018-1093: Wen Xu discovered that the ext4 filesystem implementation in the
Linux kernel did not properly handle corrupted meta data in some situations. An
attacker could use this to specially craft an ext4 filesystem that caused a
CVE-2018-1108: Jann Horn discovered that the Linux kernel's implementation of random
seed data reported that it was in a ready state before it had gathered sufficient
entropy. An attacker could use this to expose sensitive information.
CVE-2018-1118: It was discovered that the VirtIO subsystem in the Linux kernel did
not properly initialize memory in some situations. A local attacker could use
this to possibly expose sensitive information (kernel memory).
CVE-2018-1120: It was discovered that the procfs filesystem did not properly handle
processes mapping some memory elements onto files. A local attacker could use
this to block utilities that examine the procfs filesystem to report operating
system state, such as ps(1).
CVE-2018-11412: Jann Horn discovered that the ext4 filesystem implementation in
the Linux kernel did not properly keep xattr information consistent in some situations.
An attacker could use this to construct a malicious ext4 image that, when mounted,
could cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2018-12232: Shankara Pailoor discovered that a race condition existed in the
socket handling code in the Linux kernel. A local attacker could use this to cause
a denial of service (system crash).
CVE-2018-12233: Shankara Pailoor discovered that the JFS filesystem implementation
in the Linux kernel contained a buffer overflow when handling extended attributes.
A local attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code.
CVE-2018-12904: Felix Wilhelm discovered that the KVM implementation in the Linux
kernel did not properly perform permission checks in some situations when nested
virtualization is used. An attacker in a guest VM could possibly use this to escape
into an outer VM or the host OS.
CVE-2018-13406: Silvio Cesare discovered that the generic VESA frame buffer driver
in the Linux kernel contained an integer overflow. A local attacker could use
this to cause a denial of service (system crash) or possibly execute arbitrary
code.
CVE-2018-14633: It was discovered that a stack-based buffer overflow existed in
the iSCSI target implementation of the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash).
CVE-2018-14734: Noam Rathaus discovered that a use-after-free vulnerability existed
in the Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash).
CVE-2018-15471: Felix Wilhelm discovered that the Xen netback driver in the Linux
kernel did not properly perform input validation in some situations. An attacker
could use this to cause a denial of service (system crash) or possibly execute
arbitrary code.
CVE-2018-15594: It was discovered that the paravirtualization implementation in
the Linux kernel did not properly handle some indirect calls, reducing the effectiveness
of Spectre v2 mitigations for paravirtual guests. A local attacker could use this
to expose sensitive information.
CVE-2018-16276: It was discovered that the YUREX USB device driver for the Linux
kernel did not properly restrict user space reads or writes. A physically proximate
attacker could use this to cause a denial of service (system crash) or possibly
execute arbitrary code.
CVE-2018-16658: It was discovered that an integer overflow existed in the CD-ROM
driver of the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory).
CVE-2018-18955: Jann Horn discovered that the Linux kernel mishandles mapping UID
or GID ranges inside nested user namespaces in some situations. A local attacker
could use this to bypass access controls on resources outside the namespace.
CVE-2018-6559: Philipp Wendler discovered that the overlayfs implementation in the
Linux kernel did not properly verify the directory contents permissions from within
a unprivileged user namespace. A local attacker could use this to expose sensitive
information (protected file names).
CVE-2018-9363: It was discovered that an integer overflow existed in the HID Bluetooth
implementation in the Linux kernel that could lead to a buffer overwrite. An attacker
could use this to cause a denial of service (system crash) or possibly execute
arbitrary code.
cvelist: [CVE-2017-13168, CVE-2018-10876, CVE-2018-10877, CVE-2018-10878, CVE-2018-10879,
CVE-2018-10881, CVE-2018-10882, CVE-2018-10902, CVE-2018-13406, CVE-2018-14633,
CVE-2018-14734, CVE-2018-15471, CVE-2018-15594, CVE-2018-16276, CVE-2018-16658,
CVE-2018-9363, CVE-2017-13695, CVE-2018-6559, CVE-2018-1118, CVE-2018-1000200,
CVE-2018-1000204, CVE-2018-1032, CVE-2018-10840, CVE-2018-1093, CVE-2018-1108,
CVE-2018-1120, CVE-2018-11412, CVE-2018-12232, CVE-2018-12233, CVE-2018-12904,
CVE-2018-18955]
latest-version: 4.15.0-39.42~16.04.1