blob: 3d930da845e629db1cc9e032010ba5139393a0d6 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
|
Package : linux
CVE ID : CVE-2018-1087 CVE-2018-8897
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation or denial of service.
CVE-2018-1087
Andy Lutomirski discovered that the KVM implementation did not
properly handle #DB exceptions while deferred by MOV SS/POP SS,
allowing an unprivileged KVM guest user to crash the guest or
potentially escalate their privileges.
CVE-2018-8897
Nick Peterson of Everdox Tech LLC discovered that #DB exceptions
that are deferred by MOV SS or POP SS are not properly handled,
allowing an unprivileged user to crash the kernel and cause a denial
of service.
For the oldstable distribution (jessie), these problems have been fixed
in 3.16.56-1+deb8u1. This update includes various fixes for regressions
from 3.16.56-1 as released in DSA-4187-1 (Cf. #897427, #898067 and
#898100).
For the stable distribution (stretch), these problems have been fixed in
4.9.88-1+deb9u1. The fix for CVE-2018-1108 applied in DSA-4188-1 is
temporarily reverted due to various regression, cf. #897599.
|