summaryrefslogtreecommitdiffstats
path: root/dsa-texts/4.9.88-1+deb9u1
blob: 3d930da845e629db1cc9e032010ba5139393a0d6 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
Package        : linux
CVE ID         : CVE-2018-1087 CVE-2018-8897


Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation or denial of service.

CVE-2018-1087

    Andy Lutomirski discovered that the KVM implementation did not
    properly handle #DB exceptions while deferred by MOV SS/POP SS,
    allowing an unprivileged KVM guest user to crash the guest or
    potentially escalate their privileges.

CVE-2018-8897

    Nick Peterson of Everdox Tech LLC discovered that #DB exceptions
    that are deferred by MOV SS or POP SS are not properly handled,
    allowing an unprivileged user to crash the kernel and cause a denial
    of service.

For the oldstable distribution (jessie), these problems have been fixed
in 3.16.56-1+deb8u1. This update includes various fixes for regressions
from 3.16.56-1 as released in DSA-4187-1 (Cf. #897427, #898067 and
#898100).

For the stable distribution (stretch), these problems have been fixed in
4.9.88-1+deb9u1. The fix for CVE-2018-1108 applied in DSA-4188-1 is
temporarily reverted due to various regression, cf. #897599.

© 2014-2024 Faster IT GmbH | imprint | privacy policy