Ubuntu kernels patched

3 views
Skip to first unread message

Igor Seletskiy

unread,
Dec 28, 2017, 3:40:20 PM12/28/17
to kernelca...@googlegroups.com
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.

You can manually update the server by running:
# /usr/bin/kcarectl --update

Changelog:
TAGNAME: update-2017-12-28-3

ubuntu-trusty:
  CVE-2017-16939: The Linux kernel is vulerable to a use-after-free flaw when Transformation
    User configuration interface(CONFIG_XFRM_USER) compile-time configuration were
    enabled. This vulnerability occurs while closing a xfrm netlink socket in xfrm_dump_policy_done.
    A user/process could abuse this flaw to potentially escalate their privileges
    on a system.
  CVE-2017-8824: A use-after-free vulnerability was found in DCCP socket code affecting
    the Linux kernel since 2.6.16. This vulnerability could allow an attacker to their
    escalate privileges.
  KCARE-643: Adjust handling of functions names when generating patched code.
  buglist: [KCARE-643]
  cvelist: [CVE-2017-8824, CVE-2017-16939]
  latest-version: 3.

Regards,
Igor Seletskiy |  CEO
CloudLinux OS   |   KernelCare   |   Imunify360

Get 24/7 free, exceptionally good support at cloudlinux.zendesk.com
Follow us on twitter for technical updates: @CloudLinuxOS
Reply all
Reply to author
Forward
0 new messages