ALT-PU-2018-1782-1
Package kernel-image-std-def updated to version 4.9.101-alt0.M80P.1 for branch p8 in task 206719.
Closed vulnerabilities
Published: 2018-05-17
BDU:2020-03305
Уязвимость функции mmap()ing ядра операционных систем Linux, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (5.3)
Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity: MEDIUM (6.3)
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C
References:
Published: 2018-06-20
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-1120
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the /proc/
Severity: LOW (3.5)
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P
Severity: MEDIUM (5.3)
Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
- http://seclists.org/oss-sec/2018/q2/122
- http://www.securityfocus.com/bid/104229
- https://access.redhat.com/errata/RHSA-2018:2948
- https://access.redhat.com/errata/RHSA-2018:3083
- https://access.redhat.com/errata/RHSA-2018:3096
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1120
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7f7ccc2ccc2e70c6054685f5e3522efa81556830
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
- https://security.gentoo.org/glsa/201805-14
- https://usn.ubuntu.com/3752-1/
- https://usn.ubuntu.com/3752-2/
- https://usn.ubuntu.com/3752-3/
- https://usn.ubuntu.com/3910-1/
- https://usn.ubuntu.com/3910-2/
- https://www.exploit-db.com/exploits/44806/
- http://seclists.org/oss-sec/2018/q2/122
- http://www.securityfocus.com/bid/104229
- https://access.redhat.com/errata/RHSA-2018:2948
- https://access.redhat.com/errata/RHSA-2018:3083
- https://access.redhat.com/errata/RHSA-2018:3096
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1120
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7f7ccc2ccc2e70c6054685f5e3522efa81556830
- https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html
- https://security.gentoo.org/glsa/201805-14
- https://usn.ubuntu.com/3752-1/
- https://usn.ubuntu.com/3752-2/
- https://usn.ubuntu.com/3752-3/
- https://usn.ubuntu.com/3910-1/
- https://usn.ubuntu.com/3910-2/
- https://www.exploit-db.com/exploits/44806/