ALT-PU-2017-2044-1
Package kernel-image-std-def updated to version 4.9.42-alt1 for branch sisyphus in task 186996.
Closed vulnerabilities
BDU:2017-01958
Уязвимость ядра операционной системы Linux, существующая из-за отсутствия проверки длины буфера, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2017-02025
Уязвимость функции sanity_check_ckpt операционной системы Linux, позволяющая нарушителю повысить свои привилегии
Modified: 2024-11-21
CVE-2017-10663
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15d3042a937c13f5d9244241c7a9c8416ff6e82a
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15d3042a937c13f5d9244241c7a9c8416ff6e82a
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.4
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.4
- 100215
- 100215
- https://bugzilla.redhat.com/show_bug.cgi?id=1481149
- https://bugzilla.redhat.com/show_bug.cgi?id=1481149
- https://github.com/torvalds/linux/commit/15d3042a937c13f5d9244241c7a9c8416ff6e82a
- https://github.com/torvalds/linux/commit/15d3042a937c13f5d9244241c7a9c8416ff6e82a
- https://source.android.com/security/bulletin/2017-08-01
- https://source.android.com/security/bulletin/2017-08-01
Modified: 2024-11-21
CVE-2017-12762
In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tree, and 4.4-stable tree.
- [oss-security] 20200211 Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200211 Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200211 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200211 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200214 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- [oss-security] 20200214 Re: Potential regression and/or incomplete fix for CVE-2017-12762
- 100251
- 100251
- https://patchwork.kernel.org/patch/9880041/
- https://patchwork.kernel.org/patch/9880041/
- USN-3620-1
- USN-3620-1
- USN-3620-2
- USN-3620-2