ALT-PU-2015-2871-1

Обновление пакета kernel-image-std-def в ветке sisyphus

Версия3.18.22-alt1
Задание#150779
Опубликовано2015-10-06
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (2)

CVE-2015-3290
HIGH7.2

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window.

Опубликовано: 2015-08-31Изменено: 2025-04-12
CVSS 2.0ВЫСОКАЯ 7.2
CVSS:2.0/AV:L/AC:L/Au:N/C:C/I:C/A:C
Ссылки
CVE-2015-5157
HIGH7.2

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.

Опубликовано: 2015-08-31Изменено: 2025-04-12
CVSS 2.0ВЫСОКАЯ 7.2
CVSS:2.0/AV:L/AC:L/Au:N/C:C/I:C/A:C
Ссылки