Все бюллетени/c8/ALT-PU-2018-2262-1
ALT-PU-2018-2262-1

Обновление пакета kernel-image-std-def в ветке c8

Версия4.4.153-alt0.M80C.1
Задание#212053
Опубликовано2018-09-01
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (1)

CVE-2017-17053
HIGH7.0

The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT table allocation when forking a new process, allowing a local attacker to achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program. This vulnerability only affected kernels built with CONFIG_MODIFY_LDT_SYSCALL=y.

Опубликовано: 2017-11-29Изменено: 2025-04-20
CVSS 2.0СРЕДНЯЯ 6.9
CVSS:2.0/AV:L/AC:M/Au:N/C:C/I:C/A:C
CVSS 3.xВЫСОКАЯ 7.0
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H