Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
Astra Linux SE 1.5
Astra Linux SE 1.6
Astra Linux SE 1.7
Astra Linux SE 1.8
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:com.altx-soft.nix:def:28282
[Rus]
Version
9
Class
patch
ALTXid
164306
Language
English
Severity
High
Title
SUSE-SU-2017:1853-1 -- Security update for the Linux Kernel
Description
The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.74 to receive various security and bugfixes.
Family
unix
Platform
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server 12
Product
Linux kernel
Reference
VENDOR: SUSE-SU-2017:1853-1
VENDOR: SUSE-SU-2017:1853-1
Id:
SUSE-SU-2017:1853-1
Reference:
https://www.suse.com/support/update/announcement/2017/suse-su-20171853-1.html
CVE: CVE-2017-1000365
CVE: CVE-2017-1000365
Id:
CVE-2017-1000365
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000365
Comment
: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
References:
DSA-3927 (DEBIAN)
DSA-3945 (DEBIAN)
99156 (BID)
https://access.redhat.com/security/cve/CVE-2017-1000365 (CONFIRM)
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt (MISC)
CVE: CVE-2017-1000380
CVE: CVE-2017-1000380
Id:
CVE-2017-1000380
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000380
Comment
: sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ba3021b2c79b2fa9114f92790a99deb27a65b728 (MISC)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d11662f4f798b50d8c8743f433842c3e40fe3378 (MISC)
DSA-3981 (DEBIAN)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.5 (MISC)
http://www.openwall.com/lists/oss-security/2017/06/12/2 (MISC)
99121 (BID)
RHSA-2017:3295 (REDHAT)
RHSA-2017:3315 (REDHAT)
RHSA-2017:3322 (REDHAT)
https://github.com/torvalds/linux/commit/ba3021b2c79b2fa9114f92790a99deb27a65b728 (MISC)
https://github.com/torvalds/linux/commit/d11662f4f798b50d8c8743f433842c3e40fe3378 (MISC)
https://source.android.com/security/bulletin/pixel/2017-12-01 (CONFIRM)
CVE: CVE-2017-7346
CVE: CVE-2017-7346
Id:
CVE-2017-7346
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7346
Comment
: The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
20 (Improper Input Validation)
References:
https://lists.freedesktop.org/archives/dri-devel/2017-March/137429.html (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1437431 (CONFIRM)
http://marc.info/?l=linux-kernel&m=149086968410117&w=2 (CONFIRM)
97257 (BID)
DSA-3945 (DEBIAN)
DSA-3927 (DEBIAN)
CVE: CVE-2017-9242
CVE: CVE-2017-9242
Id:
CVE-2017-9242
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9242
Comment
: The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
20 (Improper Input Validation)
References:
https://patchwork.ozlabs.org/patch/764880/ (CONFIRM)
https://github.com/torvalds/linux/commit/232cd35d0804cc241eb887bb8d4d9b3b9881c64a (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=232cd35d0804cc241eb887bb8d4d9b3b9881c64a (CONFIRM)
98731 (BID)
DSA-3886 (DEBIAN)
RHSA-2017:2077 (REDHAT)
RHSA-2017:1842 (REDHAT)
CVE: CVE-2017-9076
CVE: CVE-2017-9076
Id:
CVE-2017-9076
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9076
Comment
: The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
https://patchwork.ozlabs.org/patch/760370/ (CONFIRM)
https://github.com/torvalds/linux/commit/83eaddab4378db256d00d295bda6ca997cd13a52 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=83eaddab4378db256d00d295bda6ca997cd13a52 (CONFIRM)
98586 (BID)
https://source.android.com/security/bulletin/2017-09-01 (CONFIRM)
DSA-3886 (DEBIAN)
RHSA-2017:2669 (REDHAT)
RHSA-2017:2077 (REDHAT)
RHSA-2017:1842 (REDHAT)
RHSA-2018:1854 (REDHAT)
CVE: CVE-2017-8890
CVE: CVE-2017-8890
Id:
CVE-2017-8890
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8890
Comment
: The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
415 (Double Free)
References:
https://github.com/torvalds/linux/commit/657831ffc38e30092a2d5f03d385d710eb88b09a (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=657831ffc38e30092a2d5f03d385d710eb88b09a (CONFIRM)
98562 (BID)
https://source.android.com/security/bulletin/2017-09-01 (CONFIRM)
DSA-3886 (DEBIAN)
RHSA-2017:2669 (REDHAT)
RHSA-2017:2077 (REDHAT)
RHSA-2017:1842 (REDHAT)
RHSA-2018:1854 (REDHAT)
CVE: CVE-2017-9077
CVE: CVE-2017-9077
Id:
CVE-2017-9077
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9077
Comment
: The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
https://patchwork.ozlabs.org/patch/760370/ (CONFIRM)
https://github.com/torvalds/linux/commit/83eaddab4378db256d00d295bda6ca997cd13a52 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=83eaddab4378db256d00d295bda6ca997cd13a52 (CONFIRM)
98583 (BID)
DSA-3886 (DEBIAN)
https://source.android.com/security/bulletin/2017-11-01 (CONFIRM)
RHSA-2017:2669 (REDHAT)
RHSA-2017:2077 (REDHAT)
RHSA-2017:1842 (REDHAT)
RHSA-2018:1854 (REDHAT)
CVE: CVE-2017-9075
CVE: CVE-2017-9075
Id:
CVE-2017-9075
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9075
Comment
: The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
https://patchwork.ozlabs.org/patch/763569/ (CONFIRM)
https://github.com/torvalds/linux/commit/fdcee2cbb8438702ea1b328fb6e0ac5e9a40c7f8 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fdcee2cbb8438702ea1b328fb6e0ac5e9a40c7f8 (CONFIRM)
98597 (BID)
https://source.android.com/security/bulletin/2017-10-01 (CONFIRM)
DSA-3886 (DEBIAN)
RHSA-2017:2669 (REDHAT)
RHSA-2017:2077 (REDHAT)
RHSA-2017:1842 (REDHAT)
RHSA-2018:1854 (REDHAT)
CVE: CVE-2017-9074
CVE: CVE-2017-9074
Id:
CVE-2017-9074
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9074
Comment
: The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
125 (Out-of-bounds Read)
References:
https://patchwork.ozlabs.org/patch/763117/ (CONFIRM)
https://github.com/torvalds/linux/commit/2423496af35d94a87156b063ea5cedffc10a70a1 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2423496af35d94a87156b063ea5cedffc10a70a1 (CONFIRM)
98577 (BID)
DSA-3886 (DEBIAN)
RHSA-2017:2669 (REDHAT)
RHSA-2017:2077 (REDHAT)
RHSA-2017:1842 (REDHAT)
RHSA-2018:0169 (REDHAT)
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 (CONFIRM)
CVE: CVE-2017-8924
CVE: CVE-2017-8924
Id:
CVE-2017-8924
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8924
Comment
: The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
4.6
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE:
191 (Integer Underflow (Wrap or Wraparound))
References:
https://github.com/torvalds/linux/commit/654b404f2a222f918af9b0cd18ad469d0c941a8e (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.4 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=654b404f2a222f918af9b0cd18ad469d0c941a8e (CONFIRM)
98451 (BID)
DSA-3886 (DEBIAN)
CVE: CVE-2017-8925
CVE: CVE-2017-8925
Id:
CVE-2017-8925
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8925
Comment
: The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
404 (Improper Resource Shutdown or Release)
References:
https://github.com/torvalds/linux/commit/30572418b445d85fcfe6c8fe84c947d2606767d8 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.4 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=30572418b445d85fcfe6c8fe84c947d2606767d8 (CONFIRM)
98462 (BID)
DSA-3886 (DEBIAN)
CVE: CVE-2017-7487
CVE: CVE-2017-7487
Id:
CVE-2017-7487
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7487
Comment
: The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
416 (Use After Free)
References:
https://patchwork.ozlabs.org/patch/757549/ (CONFIRM)
https://github.com/torvalds/linux/commit/ee0d8d8482345ff97a75a7d747efc309f13b0d80 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=1447734 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ee0d8d8482345ff97a75a7d747efc309f13b0d80 (CONFIRM)
98439 (BID)
1039237 (SECTRACK)
https://source.android.com/security/bulletin/2017-09-01 (CONFIRM)
DSA-3886 (DEBIAN)
CVE: CVE-2017-9150
CVE: CVE-2017-9150
Id:
CVE-2017-9150
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9150
Comment
: The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/0d0e57697f162da4aa218b5feafe614fb666db07 (MISC)
https://bugs.chromium.org/p/project-zero/issues/detail?id=1251 (MISC)
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.1 (MISC)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0d0e57697f162da4aa218b5feafe614fb666db07 (MISC)
98635 (BID)
42048 (EXPLOIT-DB)
https://source.android.com/security/bulletin/2017-09-01 (CONFIRM)
CVE: CVE-2017-7618
CVE: CVE-2017-7618
Id:
CVE-2017-7618
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7618
Comment
: crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
http://marc.info/?l=linux-crypto-vger&m=149181655623850&w=2 (MISC)
97534 (BID)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03800en_us (CONFIRM)
CVE: CVE-2017-7616
CVE: CVE-2017-7616
Id:
CVE-2017-7616
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7616
Comment
: Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE:
388 (Error Handling)
References:
https://github.com/torvalds/linux/commit/cf01fb9985e8deb25ccf0ea54d916b8871ae0e62 (CONFIRM)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cf01fb9985e8deb25ccf0ea54d916b8871ae0e62 (CONFIRM)
97527 (BID)
1038503 (SECTRACK)
https://source.android.com/security/bulletin/2017-09-01 (CONFIRM)
RHSA-2017:2077 (REDHAT)
RHSA-2017:1842 (REDHAT)
RHSA-2018:1854 (REDHAT)
Content available only for registered users!
ovaldb@altx-soft.com