2017-08-13
ALT-BU-2017-3294-1
Branch sisyphus update bulletin.
Package kernel-image-un-def updated to version 4.12.6-alt1 for branch sisyphus in task 186999.
Closed vulnerabilities
Published: 2017-08-02
BDU:2017-01958
Уязвимость ядра операционной системы Linux, существующая из-за отсутствия проверки длины буфера, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2017-08-10
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-12762
In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tree, and 4.4-stable tree.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- [oss-security] 20200211 Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200211 Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200211 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200211 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200214 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200214 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- 100251
- 100251
- https://patchwork.kernel.org/patch/9880041/
- https://patchwork.kernel.org/patch/9880041/
- USN-3620-1
- USN-3620-1
- USN-3620-2
- USN-3620-2