Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
Astra Linux SE 1.5
Astra Linux SE 1.6
Astra Linux SE 1.7
Astra Linux SE 1.8
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:com.altx-soft.nix:def:16551
[Rus]
Version
8
Class
patch
ALTXid
170043
Language
English
Severity
High
Title
SUSE-SU-2018:0040-1 -- Security update for Linux Kernel
Description
The SUSE Linux Enterprise 11 SP3 LTSS kernel was updated to receive various security and bugfixes.
Family
unix
Platform
SUSE Linux Enterprise Server 11
Product
Linux Kernel
Reference
VENDOR: SUSE-SU-2018:0040-1
VENDOR: SUSE-SU-2018:0040-1
Id:
SUSE-SU-2018:0040-1
Reference:
https://www.suse.com/support/update/announcement/2018/suse-su-20180040-1.html
CVE: CVE-2017-5753
CVE: CVE-2017-5753
Id:
CVE-2017-5753
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5753
Comment
: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
203 (Information Exposure Through Discrepancy)
References:
https://www.synology.com/support/security/Synology_SA_18_01 (CONFIRM)
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ (CONFIRM)
https://support.lenovo.com/us/en/solutions/LEN-18282 (CONFIRM)
https://support.f5.com/csp/article/K91229003 (CONFIRM)
https://spectreattack.com/ (MISC)
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html (MISC)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 (CONFIRM)
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html (MISC)
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ (CONFIRM)
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ (CONFIRM)
https://access.redhat.com/security/vulnerabilities/speculativeexecution (CONFIRM)
http://xenbits.xen.org/xsa/advisory-254.html (CONFIRM)
1040071 (SECTRACK)
VU#584653 (CERT-VN)
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 (CONFIRM)
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html (CONFIRM)
43427 (EXPLOIT-DB)
20180104 CPU Side-Channel Information Disclosure Vulnerabilities (CISCO)
https://support.citrix.com/article/CTX231399 (CONFIRM)
https://security.netapp.com/advisory/ntap-20180104-0001/ (CONFIRM)
102371 (BID)
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html (MISC)
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 (CONFIRM)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us (CONFIRM)
USN-3516-1 (UBUNTU)
RHSA-2018:0292 (REDHAT)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt (CONFIRM)
USN-3597-2 (UBUNTU)
USN-3597-1 (UBUNTU)
USN-3580-1 (UBUNTU)
USN-3549-1 (UBUNTU)
USN-3542-1 (UBUNTU)
USN-3541-1 (UBUNTU)
USN-3540-1 (UBUNTU)
USN-3542-2 (UBUNTU)
USN-3541-2 (UBUNTU)
USN-3540-2 (UBUNTU)
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html (CONFIRM)
DSA-4188 (DEBIAN)
DSA-4187 (DEBIAN)
https://cert.vde.com/en-us/advisories/vde-2018-003 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-002 (CONFIRM)
VU#180049 (CERT-VN)
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability (CONFIRM)
[debian-lts-announce] 20180715 [SECURITY] [DLA 1422-2] linux security update (MLIST)
[debian-lts-announce] 20180714 [SECURITY] [DLA 1422-1] linux security update (MLIST)
[debian-lts-announce] 20180718 [SECURITY] [DLA 1423-1] linux-4.9 new package (MLIST)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us (CONFIRM)
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 (CONFIRM)
GLSA-201810-06 (GENTOO)
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf (CONFIRM)
[debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update (MLIST)
[debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update (MLIST)
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html (MISC)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
https://cdrdv2.intel.com/v1/dl/getContent/685359 (CONFIRM)
CVE: CVE-2017-5715
CVE: CVE-2017-5715
Id:
CVE-2017-5715
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715
Comment
: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
203 (Information Exposure Through Discrepancy)
References:
https://www.synology.com/support/security/Synology_SA_18_01 (CONFIRM)
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ (CONFIRM)
https://support.lenovo.com/us/en/solutions/LEN-18282 (CONFIRM)
https://support.f5.com/csp/article/K91229003 (CONFIRM)
https://spectreattack.com/ (MISC)
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr (CONFIRM)
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html (MISC)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 (CONFIRM)
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html (MISC)
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ (CONFIRM)
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ (CONFIRM)
https://access.redhat.com/security/vulnerabilities/speculativeexecution (CONFIRM)
http://xenbits.xen.org/xsa/advisory-254.html (CONFIRM)
1040071 (SECTRACK)
VU#584653 (CERT-VN)
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 (CONFIRM)
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html (CONFIRM)
43427 (EXPLOIT-DB)
20180104 CPU Side-Channel Information Disclosure Vulnerabilities (CISCO)
https://support.citrix.com/article/CTX231399 (CONFIRM)
https://security.netapp.com/advisory/ntap-20180104-0001/ (CONFIRM)
102376 (BID)
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html (MISC)
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 (CONFIRM)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0020 (SUSE)
SUSE-SU-2018:0019 (SUSE)
openSUSE-SU-2018:0013 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
SUSE-SU-2018:0009 (SUSE)
SUSE-SU-2018:0008 (SUSE)
SUSE-SU-2018:0007 (SUSE)
SUSE-SU-2018:0006 (SUSE)
https://www.vmware.com/us/security/advisories/VMSA-2018-0004.html (CONFIRM)
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us (CONFIRM)
USN-3516-1 (UBUNTU)
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html (CONFIRM)
RHSA-2018:0292 (REDHAT)
DSA-4120 (DEBIAN)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt (CONFIRM)
FreeBSD-SA-18:03 (FREEBSD)
USN-3597-2 (UBUNTU)
USN-3597-1 (UBUNTU)
USN-3594-1 (UBUNTU)
USN-3582-2 (UBUNTU)
USN-3582-1 (UBUNTU)
USN-3581-2 (UBUNTU)
USN-3581-1 (UBUNTU)
USN-3580-1 (UBUNTU)
USN-3561-1 (UBUNTU)
USN-3560-1 (UBUNTU)
USN-3549-1 (UBUNTU)
USN-3531-1 (UBUNTU)
USN-3542-2 (UBUNTU)
https://www.vmware.com/security/advisories/VMSA-2018-0007.html (CONFIRM)
USN-3541-2 (UBUNTU)
USN-3540-2 (UBUNTU)
USN-3531-3 (UBUNTU)
USN-3620-2 (UBUNTU)
DSA-4188 (DEBIAN)
DSA-4187 (DEBIAN)
[debian-lts-announce] 20180502 [SECURITY] [DLA 1369-1] linux security update (MLIST)
https://cert.vde.com/en-us/advisories/vde-2018-003 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-002 (CONFIRM)
VU#180049 (CERT-VN)
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability (CONFIRM)
DSA-4213 (DEBIAN)
USN-3690-1 (UBUNTU)
[debian-lts-announce] 20180715 [SECURITY] [DLA 1422-2] linux security update (MLIST)
[debian-lts-announce] 20180714 [SECURITY] [DLA 1422-1] linux security update (MLIST)
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html (CONFIRM)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us (CONFIRM)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
[debian-lts-announce] 20180916 [SECURITY] [DLA 1506-1] intel-microcode security update (MLIST)
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html (CONFIRM)
USN-3777-3 (UBUNTU)
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 (CONFIRM)
GLSA-201810-06 (GENTOO)
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes (CONFIRM)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html (MISC)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
FreeBSD-SA-19:26 (FREEBSD)
20191112 FreeBSD Security Advisory FreeBSD-SA-19:26.mcu (BUGTRAQ)
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html (MISC)
https://security.paloaltonetworks.com/CVE-2017-5715 (CONFIRM)
[debian-lts-announce] 20200320 [SECURITY] [DLA 2148-1] amd64-microcode security update (MLIST)
[debian-lts-announce] 20210816 [SECURITY] [DLA 2743-1] amd64-microcode security update (MLIST)
CVE: CVE-2017-5754
CVE: CVE-2017-5754
Id:
CVE-2017-5754
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754
Comment
: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://www.synology.com/support/security/Synology_SA_18_01 (CONFIRM)
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ (CONFIRM)
https://support.lenovo.com/us/en/solutions/LEN-18282 (CONFIRM)
https://support.f5.com/csp/article/K91229003 (CONFIRM)
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html (MISC)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 (CONFIRM)
https://meltdownattack.com/ (MISC)
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html (MISC)
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ (CONFIRM)
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ (CONFIRM)
https://access.redhat.com/security/vulnerabilities/speculativeexecution (CONFIRM)
http://xenbits.xen.org/xsa/advisory-254.html (CONFIRM)
1040071 (SECTRACK)
VU#584653 (CERT-VN)
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 (CONFIRM)
DSA-4078 (DEBIAN)
20180104 CPU Side-Channel Information Disclosure Vulnerabilities (CISCO)
https://support.citrix.com/article/CTX231399 (CONFIRM)
https://security.netapp.com/advisory/ntap-20180104-0001/ (CONFIRM)
102378 (BID)
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 (CONFIRM)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
DSA-4082 (DEBIAN)
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us (CONFIRM)
USN-3525-1 (UBUNTU)
USN-3524-2 (UBUNTU)
USN-3523-2 (UBUNTU)
USN-3522-2 (UBUNTU)
USN-3516-1 (UBUNTU)
[debian-lts-announce] 20180107 [SECURITY] [DLA 1232-1] linux security update (MLIST)
RHSA-2018:0292 (REDHAT)
DSA-4120 (DEBIAN)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt (CONFIRM)
FreeBSD-SA-18:03 (FREEBSD)
USN-3597-2 (UBUNTU)
USN-3597-1 (UBUNTU)
USN-3583-1 (UBUNTU)
USN-3523-1 (UBUNTU)
USN-3522-4 (UBUNTU)
USN-3522-3 (UBUNTU)
USN-3541-2 (UBUNTU)
USN-3540-2 (UBUNTU)
https://source.android.com/security/bulletin/2018-04-01 (CONFIRM)
https://support.citrix.com/article/CTX234679 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-003 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-002 (CONFIRM)
VU#180049 (CERT-VN)
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability (CONFIRM)
https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletin (CONFIRM)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us (CONFIRM)
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 (CONFIRM)
GLSA-201810-06 (GENTOO)
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes (CONFIRM)
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 (CONFIRM)
106128 (BID)
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html (MISC)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
N/A (N/A)
https://cdrdv2.intel.com/v1/dl/getContent/685358 (CONFIRM)
CVE: CVE-2017-1000251
CVE: CVE-2017-1000251
Id:
CVE-2017-1000251
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000251
Comment
: The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
CVSSv2 Score:
8.3
Access vector:
ADJACENT_NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:L/Au:N/C:C/I:C/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://nvidia.custhelp.com/app/answers/detail/a_id/4561 (CONFIRM)
DSA-3981 (DEBIAN)
100809 (BID)
1039373 (SECTRACK)
RHSA-2017:2679 (REDHAT)
RHSA-2017:2680 (REDHAT)
RHSA-2017:2681 (REDHAT)
RHSA-2017:2682 (REDHAT)
RHSA-2017:2683 (REDHAT)
RHSA-2017:2704 (REDHAT)
RHSA-2017:2705 (REDHAT)
RHSA-2017:2706 (REDHAT)
RHSA-2017:2707 (REDHAT)
RHSA-2017:2731 (REDHAT)
RHSA-2017:2732 (REDHAT)
https://access.redhat.com/security/vulnerabilities/blueborne (CONFIRM)
https://github.com/torvalds/linux/commit/f2fcfcd670257236ebf2088bbdf26f6a8ef459fe (MISC)
https://www.armis.com/blueborne (MISC)
42762 (EXPLOIT-DB)
VU#240311 (CERT-VN)
https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne (CONFIRM)
CVE: CVE-2017-11600
CVE: CVE-2017-11600
Id:
CVE-2017-11600
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11600
Comment
: net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via an XFRM_MSG_MIGRATE xfrm Netlink message.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
125 (Out-of-bounds Read)
References:
http://seclists.org/bugtraq/2017/Jul/30 (MISC)
99928 (BID)
DSA-3981 (DEBIAN)
https://source.android.com/security/bulletin/pixel/2017-11-01 (CONFIRM)
SUSE-SU-2018:0011 (SUSE)
RHSA-2018:2003 (REDHAT)
RHSA-2018:1965 (REDHAT)
RHSA-2019:1170 (REDHAT)
RHSA-2019:1190 (REDHAT)
CVE: CVE-2017-13080
CVE: CVE-2017-13080
Id:
CVE-2017-13080
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13080
Comment
: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
CVSSv2 Score:
2.9
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:P/A:N
CVSSv3 Score:
5.3
Attack vector:
ADJACENT_NETWORK
Attack complexity:
HIGH
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
HIGH
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE:
330 (Use of Insufficiently Random Values)
References:
https://www.krackattacks.com/ (MISC)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-13080 (CONFIRM)
VU#228519 (CERT-VN)
1039585 (SECTRACK)
1039581 (SECTRACK)
1039578 (SECTRACK)
1039577 (SECTRACK)
1039576 (SECTRACK)
1039573 (SECTRACK)
1039572 (SECTRACK)
101274 (BID)
https://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txt (MISC)
20171016 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II (CISCO)
https://support.lenovo.com/us/en/product_security/LEN-17420 (CONFIRM)
FreeBSD-SA-17:07 (FREEBSD)
https://access.redhat.com/security/vulnerabilities/kracks (CONFIRM)
RHSA-2017:2911 (REDHAT)
RHSA-2017:2907 (REDHAT)
USN-3455-1 (UBUNTU)
DSA-3999 (DEBIAN)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txt (CONFIRM)
openSUSE-SU-2017:2755 (SUSE)
SUSE-SU-2017:2752 (SUSE)
SUSE-SU-2017:2745 (SUSE)
1039703 (SECTRACK)
GLSA-201711-03 (GENTOO)
https://support.apple.com/HT208222 (CONFIRM)
https://support.apple.com/HT208221 (CONFIRM)
https://support.apple.com/HT208220 (CONFIRM)
https://support.apple.com/HT208219 (CONFIRM)
https://source.android.com/security/bulletin/2017-11-01 (CONFIRM)
https://support.apple.com/HT208334 (CONFIRM)
https://support.apple.com/HT208327 (CONFIRM)
https://support.apple.com/HT208325 (CONFIRM)
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html (CONFIRM)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html (CONFIRM)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03792en_us (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdf (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2017-005 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2017-003 (CONFIRM)
[debian-lts-announce] 20181113 [SECURITY] [DLA 1573-1] firmware-nonfree security update (MLIST)
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00402.html (CONFIRM)
CVE: CVE-2017-13167
CVE: CVE-2017-13167
Id:
CVE-2017-13167
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13167
Comment
: An elevation of privilege vulnerability in the kernel sound timer. Product: Android. Versions: Android kernel. Android ID A-37240993.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
https://source.android.com/security/bulletin/pixel/2017-12-01 (CONFIRM)
SUSE-SU-2018:0011 (SUSE)
CVE: CVE-2017-14106
CVE: CVE-2017-14106
Id:
CVE-2017-14106
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14106
Comment
: The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
369 (Divide By Zero)
References:
https://github.com/torvalds/linux/commit/499350a5a6e7512d9ed369ed63a4244b6536f4f8 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=499350a5a6e7512d9ed369ed63a4244b6536f4f8 (CONFIRM)
100878 (BID)
1039549 (SECTRACK)
DSA-3981 (DEBIAN)
RHSA-2017:3200 (REDHAT)
RHSA-2017:2931 (REDHAT)
RHSA-2017:2930 (REDHAT)
RHSA-2017:2918 (REDHAT)
SUSE-SU-2018:0011 (SUSE)
RHSA-2018:2172 (REDHAT)
https://www.mail-archive.com/netdev%40vger.kernel.org/msg186255.html ()
CVE: CVE-2017-14140
CVE: CVE-2017-14140
Id:
CVE-2017-14140
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14140
Comment
: The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/197e7e521384a23b9e585178f3f11c9fa08274b9 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.9 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=197e7e521384a23b9e585178f3f11c9fa08274b9 (CONFIRM)
100876 (BID)
DSA-3981 (DEBIAN)
https://source.android.com/security/bulletin/pixel/2018-01-01 (CONFIRM)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
RHSA-2018:1062 (REDHAT)
RHSA-2018:0676 (REDHAT)
CVE: CVE-2017-14340
CVE: CVE-2017-14340
Id:
CVE-2017-14340
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14340
Comment
: The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via vectors related to setting an RHINHERIT flag on a directory.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://github.com/torvalds/linux/commit/b31ff3cdf540110da4572e3e29bd172087af65cc (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1491344 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.2 (CONFIRM)
http://seclists.org/oss-sec/2017/q3/436 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b31ff3cdf540110da4572e3e29bd172087af65cc (CONFIRM)
100851 (BID)
DSA-3981 (DEBIAN)
RHSA-2017:2918 (REDHAT)
CVE: CVE-2017-15102
CVE: CVE-2017-15102
Id:
CVE-2017-15102
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15102
Comment
: The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.3
Attack vector:
PHYSICAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://github.com/torvalds/linux/commit/2fae9e5a7babada041e2e161699ade2447a01989 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1505905 (CONFIRM)
http://seclists.org/oss-sec/2017/q4/238 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2fae9e5a7babada041e2e161699ade2447a01989 (CONFIRM)
101790 (BID)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
CVE: CVE-2017-15115
CVE: CVE-2017-15115
Id:
CVE-2017-15115
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15115
Comment
: The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
https://patchwork.ozlabs.org/patch/827077/ (CONFIRM)
https://github.com/torvalds/linux/commit/df80cd9b28b9ebaa284a41df611dbf3a2d05ca74 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1513345 (CONFIRM)
http://seclists.org/oss-sec/2017/q4/282 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=df80cd9b28b9ebaa284a41df611dbf3a2d05ca74 (CONFIRM)
101877 (BID)
SUSE-SU-2018:0011 (SUSE)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
USN-3582-2 (UBUNTU)
USN-3582-1 (UBUNTU)
USN-3581-3 (UBUNTU)
USN-3581-2 (UBUNTU)
USN-3581-1 (UBUNTU)
https://source.android.com/security/bulletin/pixel/2018-04-01 (CONFIRM)
CVE: CVE-2017-15265
CVE: CVE-2017-15265
Id:
CVE-2017-15265
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15265
Comment
: Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
https://bugzilla.suse.com/show_bug.cgi?id=1062520 (CONFIRM)
[oss-security] 20171011 Linux kernel: alsa: use-after-free in /dev/snd/seq CVE-2017-15265 (MLIST)
[alsa-devel] 20171011 [PATCH] ALSA: seq: Fix use-after-free at creating a port (MLIST)
1039561 (SECTRACK)
101288 (BID)
https://github.com/torvalds/linux/commit/71105998845fb012937332fe2e806d443c09e026 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.8 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=71105998845fb012937332fe2e806d443c09e026 (CONFIRM)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
https://source.android.com/security/bulletin/2018-02-01 (CONFIRM)
RHSA-2018:1062 (REDHAT)
RHSA-2018:0676 (REDHAT)
RHSA-2018:1170 (REDHAT)
RHSA-2018:1130 (REDHAT)
USN-3698-2 (UBUNTU)
USN-3698-1 (UBUNTU)
RHSA-2018:2390 (REDHAT)
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 (CONFIRM)
RHSA-2018:3823 (REDHAT)
RHSA-2018:3822 (REDHAT)
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html (MISC)
https://www.oracle.com/security-alerts/cpujul2020.html (MISC)
CVE: CVE-2017-15274
CVE: CVE-2017-15274
Id:
CVE-2017-15274
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15274
Comment
: security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted add_key or keyctl system call, a different vulnerability than CVE-2017-12192.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://patchwork.kernel.org/patch/9781573/ (CONFIRM)
https://github.com/torvalds/linux/commit/5649645d725c73df4302428ee4e02c869248b4c5 (CONFIRM)
https://bugzilla.suse.com/show_bug.cgi?id=1045327 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.5 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5649645d725c73df4302428ee4e02c869248b4c5 (CONFIRM)
101292 (BID)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
RHSA-2019:1946 (REDHAT)
CVE: CVE-2017-12192
CVE: CVE-2017-12192
Id:
CVE-2017-12192
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12192
Comment
: The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively instantiated, which allows local users to cause a denial of service (OOPS and system crash) via a crafted KEYCTL_READ operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://lkml.org/lkml/2017/9/18/764 (MISC)
https://bugzilla.redhat.com/show_bug.cgi?id=1493435 (CONFIRM)
https://github.com/torvalds/linux/commit/37863c43b2c6464f252862bf2e9768264e961678 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.5 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=37863c43b2c6464f252862bf2e9768264e961678 (CONFIRM)
RHSA-2018:0151 (REDHAT)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
CVE: CVE-2017-15868
CVE: CVE-2017-15868
Id:
CVE-2017-15868
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15868
Comment
: The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
20 (Improper Input Validation)
References:
https://source.android.com/security/bulletin/pixel/2017-12-01 (CONFIRM)
https://patchwork.kernel.org/patch/9882449/ (CONFIRM)
https://github.com/torvalds/linux/commit/71bb99a02b32b4cc4265118e85f6035ca72923f0 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=71bb99a02b32b4cc4265118e85f6035ca72923f0 (CONFIRM)
102084 (BID)
SUSE-SU-2018:0011 (SUSE)
DSA-4082 (DEBIAN)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
CVE: CVE-2017-16525
CVE: CVE-2017-16525
Id:
CVE-2017-16525
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16525
Comment
: The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device, related to disconnection and failed setup.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
https://groups.google.com/d/msg/syzkaller/cMACrmo1x0k/4KhRoUgABAAJ (MISC)
https://github.com/torvalds/linux/commit/bd998c2e0df0469707503023d50d46cf0b10c787 (MISC)
https://github.com/torvalds/linux/commit/299d7572e46f98534033a9e65973f13ad1ce9047 (MISC)
102028 (BID)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
CVE: CVE-2017-16527
CVE: CVE-2017-16527
Id:
CVE-2017-16527
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16527
Comment
: sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
https://groups.google.com/d/msg/syzkaller/jf7GTr_g2CU/iVlLhMciCQAJ (MISC)
https://github.com/torvalds/linux/commit/124751d5e63c823092060074bd0abaae61aaa9c4 (MISC)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3754-1 (UBUNTU)
CVE: CVE-2017-16529
CVE: CVE-2017-16529
Id:
CVE-2017-16529
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16529
Comment
: The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
125 (Out-of-bounds Read)
References:
https://groups.google.com/d/msg/syzkaller/rDzv5RP_f2M/M5au06qmAwAJ (MISC)
https://github.com/torvalds/linux/commit/bfc81a8bc18e3c4ba0cbaa7666ff76be2f998991 (MISC)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
103284 (BID)
USN-3754-1 (UBUNTU)
CVE: CVE-2017-16531
CVE: CVE-2017-16531
Id:
CVE-2017-16531
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16531
Comment
: drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION descriptor.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
https://groups.google.com/d/msg/syzkaller/hP6L-m59m_8/Co2ouWeFAwAJ (MISC)
https://github.com/torvalds/linux/commit/bd7a3fe770ebd8391d1c7d072ff88e9e76d063eb (MISC)
102025 (BID)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3754-1 (UBUNTU)
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html (MISC)
CVE: CVE-2017-16534
CVE: CVE-2017-16534
Id:
CVE-2017-16534
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16534
Comment
: The cdc_parse_cdc_header function in drivers/usb/core/message.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.8
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
https://groups.google.com/d/msg/syzkaller/nXnjqI73uPo/6sUyq6kqAgAJ (MISC)
https://github.com/torvalds/linux/commit/2e1c42391ff2556387b3cb6308b24f6f65619feb (MISC)
SUSE-SU-2018:0011 (SUSE)
CVE: CVE-2017-16535
CVE: CVE-2017-16535
Id:
CVE-2017-16535
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16535
Comment
: The usb_get_bos_descriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
125 (Out-of-bounds Read)
References:
https://groups.google.com/d/msg/syzkaller/tzdz2fTB1K0/OvjIgLSTAgAJ (MISC)
https://github.com/torvalds/linux/commit/1c0edc3633b56000e18d82fc241e3995ca18a69e (MISC)
102022 (BID)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3754-1 (UBUNTU)
CVE: CVE-2017-16536
CVE: CVE-2017-16536
Id:
CVE-2017-16536
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16536
Comment
: The cx231xx_usb_probe function in drivers/media/usb/cx231xx/cx231xx-cards.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://patchwork.kernel.org/patch/9963527/ (MISC)
https://groups.google.com/d/msg/syzkaller/WlUAVfDvpRk/1V1xuEA4AgAJ (MISC)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3619-1 (UBUNTU)
USN-3619-2 (UBUNTU)
USN-3754-1 (UBUNTU)
CVE: CVE-2017-16537
CVE: CVE-2017-16537
Id:
CVE-2017-16537
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16537
Comment
: The imon_probe function in drivers/media/rc/imon.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
476 (NULL Pointer Dereference)
References:
https://patchwork.kernel.org/patch/9994017/ (MISC)
https://groups.google.com/d/msg/syzkaller/bBFN8imrjjo/-5jCl8EiCQAJ (MISC)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3617-2 (UBUNTU)
USN-3617-1 (UBUNTU)
USN-3619-1 (UBUNTU)
USN-3617-3 (UBUNTU)
USN-3619-2 (UBUNTU)
USN-3754-1 (UBUNTU)
CVE: CVE-2017-16538
CVE: CVE-2017-16538
Id:
CVE-2017-16538
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16538
Comment
: drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing warm-start check and incorrect attach timing (dm04_lme2510_frontend_attach versus dm04_lme2510_tuner).
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
20 (Improper Input Validation)
References:
https://patchwork.linuxtv.org/patch/44567/ (MISC)
https://patchwork.linuxtv.org/patch/44566/ (MISC)
https://groups.google.com/d/msg/syzkaller/XwNidsl4X04/ti6I2IaRBAAJ (MISC)
DSA-4073 (DEBIAN)
SUSE-SU-2018:0011 (SUSE)
DSA-4082 (DEBIAN)
USN-3631-2 (UBUNTU)
USN-3631-1 (UBUNTU)
USN-3754-1 (UBUNTU)
CVE: CVE-2017-16649
CVE: CVE-2017-16649
Id:
CVE-2017-16649
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16649
Comment
: The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
369 (Divide By Zero)
References:
https://patchwork.ozlabs.org/patch/834771/ (MISC)
https://groups.google.com/d/msg/syzkaller/0e0gmaX9R0g/9Me9JcY2BQAJ (MISC)
101761 (BID)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
USN-3617-2 (UBUNTU)
USN-3617-1 (UBUNTU)
USN-3619-1 (UBUNTU)
USN-3617-3 (UBUNTU)
USN-3619-2 (UBUNTU)
USN-3822-2 (UBUNTU)
USN-3822-1 (UBUNTU)
CVE: CVE-2017-16939
CVE: CVE-2017-16939
Id:
CVE-2017-16939
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16939
Comment
: The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
https://github.com/torvalds/linux/commit/1137b5e2529a8f5ca8ee709288ecba3e68044df2 (MISC)
https://bugzilla.suse.com/show_bug.cgi?id=1069702 (MISC)
https://blogs.securiteam.com/index.php/archives/3535 (MISC)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.11 (MISC)
http://seclists.org/fulldisclosure/2017/Nov/40 (MISC)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1137b5e2529a8f5ca8ee709288ecba3e68044df2 (MISC)
101954 (BID)
SUSE-SU-2018:0011 (SUSE)
DSA-4082 (DEBIAN)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
RHSA-2018:1355 (REDHAT)
RHSA-2018:1318 (REDHAT)
RHSA-2019:1170 (REDHAT)
RHSA-2019:1190 (REDHAT)
CVE: CVE-2017-17450
CVE: CVE-2017-17450
Id:
CVE-2017-17450
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17450
Comment
: net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback and remove_callback operations, which allows local users to bypass intended access restrictions because the xt_osf_fingers data structure is shared across all net namespaces.
CVSSv2 Score:
4.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
862 (Missing Authorization)
References:
https://lkml.org/lkml/2017/12/5/982 (MISC)
102110 (BID)
DSA-4073 (DEBIAN)
SUSE-SU-2018:0011 (SUSE)
DSA-4082 (DEBIAN)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
USN-3617-2 (UBUNTU)
USN-3617-1 (UBUNTU)
USN-3619-1 (UBUNTU)
USN-3617-3 (UBUNTU)
USN-3619-2 (UBUNTU)
USN-3632-1 (UBUNTU)
CVE: CVE-2017-17558
CVE: CVE-2017-17558
Id:
CVE-2017-17558
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17558
Comment
: The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write access) or possibly have unspecified other impact via a crafted USB device.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
6.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://www.spinics.net/lists/linux-usb/msg163644.html (MISC)
http://openwall.com/lists/oss-security/2017/12/12/7 (MISC)
DSA-4073 (DEBIAN)
SUSE-SU-2018:0011 (SUSE)
DSA-4082 (DEBIAN)
[debian-lts-announce] 20180107 [SECURITY] [DLA 1232-1] linux security update (MLIST)
USN-3619-1 (UBUNTU)
USN-3619-2 (UBUNTU)
RHSA-2018:1062 (REDHAT)
RHSA-2018:0676 (REDHAT)
USN-3754-1 (UBUNTU)
RHSA-2019:1170 (REDHAT)
RHSA-2019:1190 (REDHAT)
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html (MISC)
CVE: CVE-2017-17805
CVE: CVE-2017-17805
Id:
CVE-2017-17805
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17805
Comment
: The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified other impact by executing a crafted sequence of system calls that use the blkcipher_walk API. Both the generic implementation (crypto/salsa20_generic.c) and x86 implementation (arch/x86/crypto/salsa20_glue.c) of Salsa20 were vulnerable.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
20 (Improper Input Validation)
References:
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8 (CONFIRM)
https://github.com/torvalds/linux/commit/ecaaab5649781c5a0effdaf298a925063020500e (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ecaaab5649781c5a0effdaf298a925063020500e (CONFIRM)
DSA-4073 (DEBIAN)
102291 (BID)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
DSA-4082 (DEBIAN)
[debian-lts-announce] 20180107 [SECURITY] [DLA 1232-1] linux security update (MLIST)
USN-3617-2 (UBUNTU)
USN-3617-1 (UBUNTU)
USN-3620-2 (UBUNTU)
USN-3620-1 (UBUNTU)
USN-3619-1 (UBUNTU)
USN-3617-3 (UBUNTU)
USN-3619-2 (UBUNTU)
USN-3632-1 (UBUNTU)
RHSA-2018:3096 (REDHAT)
RHSA-2018:3083 (REDHAT)
RHSA-2018:2948 (REDHAT)
RHSA-2019:2473 (REDHAT)
CVE: CVE-2017-17806
CVE: CVE-2017-17806
Id:
CVE-2017-17806
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17806
Comment
: The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8 (CONFIRM)
https://github.com/torvalds/linux/commit/af3ff8045bbf3e32f1a448542e73abb4c8ceb6f1 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=af3ff8045bbf3e32f1a448542e73abb4c8ceb6f1 (CONFIRM)
DSA-4073 (DEBIAN)
102293 (BID)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
DSA-4082 (DEBIAN)
[debian-lts-announce] 20180107 [SECURITY] [DLA 1232-1] linux security update (MLIST)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
USN-3617-2 (UBUNTU)
USN-3617-1 (UBUNTU)
USN-3619-1 (UBUNTU)
USN-3617-3 (UBUNTU)
USN-3619-2 (UBUNTU)
USN-3632-1 (UBUNTU)
RHSA-2018:2948 (REDHAT)
CVE: CVE-2017-7472
CVE: CVE-2017-7472
Id:
CVE-2017-7472
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7472
Comment
: The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
404 (Improper Resource Shutdown or Release)
References:
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.13 (CONFIRM)
https://lkml.org/lkml/2017/4/3/724 (CONFIRM)
https://lkml.org/lkml/2017/4/1/235 (CONFIRM)
https://github.com/torvalds/linux/commit/c9f838d104fed6f2f61d68164712e3204bf5271b (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1442086 (CONFIRM)
https://bugzilla.novell.com/show_bug.cgi?id=1034862 (CONFIRM)
http://openwall.com/lists/oss-security/2017/05/11/1 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c9f838d104fed6f2f61d68164712e3204bf5271b (CONFIRM)
98422 (BID)
1038471 (SECTRACK)
42136 (EXPLOIT-DB)
SUSE-SU-2018:0011 (SUSE)
RHSA-2018:0181 (REDHAT)
RHSA-2018:0152 (REDHAT)
RHSA-2018:0151 (REDHAT)
CVE: CVE-2017-8824
CVE: CVE-2017-8824
Id:
CVE-2017-8824
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8824
Comment
: The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
http://www.openwall.com/lists/oss-security/2017/12/05/1 (MISC)
http://lists.openwall.net/netdev/2017/12/04/224 (MISC)
102056 (BID)
43234 (EXPLOIT-DB)
DSA-4073 (DEBIAN)
SUSE-SU-2018:0011 (SUSE)
DSA-4082 (DEBIAN)
[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update (MLIST)
RHSA-2018:0399 (REDHAT)
USN-3583-2 (UBUNTU)
USN-3583-1 (UBUNTU)
USN-3582-2 (UBUNTU)
USN-3582-1 (UBUNTU)
USN-3581-3 (UBUNTU)
USN-3581-2 (UBUNTU)
USN-3581-1 (UBUNTU)
RHSA-2018:1062 (REDHAT)
RHSA-2018:0676 (REDHAT)
RHSA-2018:1170 (REDHAT)
RHSA-2018:1130 (REDHAT)
RHSA-2018:1216 (REDHAT)
RHSA-2018:1319 (REDHAT)
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 (CONFIRM)
RHSA-2018:3822 (REDHAT)
Content available only for registered users!
ovaldb@altx-soft.com