2019年7月31日 星期三

[USN-4069-1] Linux kernel vulnerabilities

---------- Forwarded message ---------
From: Steve Beattie
Date: Jul 23, 2019 3:13PM

It was discovered that an integer overflow existed in the Linux kernel when
reference counting pages, leading to potential use-after-free issues. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-11487)

Jann Horn discovered that a race condition existed in the Linux kernel when
performing core dumps. A local attacker could use this to cause a denial of
service (system crash) or expose sensitive information. (CVE-2019-11599)

It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)

It was discovered that the Bluetooth Human Interface Device Protocol (HIDP)
implementation in the Linux kernel did not properly verify strings were
NULL terminated in certain situations. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2019-11884)

References:
  https://usn.ubuntu.com/4069-1
  CVE-2019-11487, CVE-2019-11599, CVE-2019-11833, CVE-2019-11884

沒有留言:

張貼留言