Oval Definition:oval:com.ubuntu.bionic:def:2016107230000000
Revision Date:2018-06-21Version:1
Title:CVE-2016-10723 on Ubuntu 18.04 LTS (bionic) - low.
Description:** DISPUTED ** An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that "the underlying problem is non-trivial to handle."
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-10723
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND Package Information
  • linux package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-aws package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-aws-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1021.24~18.04.1').
  • OR linux-azure package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1014.14~18.04.1').
  • OR linux-azure-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1007.8~18.04.1').
  • OR linux-gcp package in bionic was vulnerable but has been fixed (note: '5.0.0-1020.20~18.04.1').
  • OR linux-gcp-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1008.9~18.04.1').
  • OR linux-gke-4.15 package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-gke-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1011.11~18.04.1').
  • OR linux-gke-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1011.12~18.04.1').
  • OR linux-hwe package in bionic was vulnerable but has been fixed (note: '5.0.0-23.24~18.04.1').
  • OR linux-kvm package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta-aws package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta-aws-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1021.24~18.04.1').
  • OR linux-meta-azure package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1014.14~18.04.1').
  • OR linux-meta-azure-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1007.8~18.04.1').
  • OR linux-meta-gcp package in bionic was vulnerable but has been fixed (note: '5.0.0-1020.20~18.04.1').
  • OR linux-meta-gcp-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1008.9~18.04.1').
  • OR linux-meta-gke-4.15 package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta-gke-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1011.11~18.04.1').
  • OR linux-meta-gke-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1011.12~18.04.1').
  • OR linux-meta-hwe package in bionic was vulnerable but has been fixed (note: '5.0.0-23.24~18.04.1').
  • OR linux-meta-kvm package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta-oem package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta-oem-osp1 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1010.11').
  • OR linux-meta-oracle package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta-oracle-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1007.12~18.04.1').
  • OR linux-meta-raspi2 package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-meta-raspi2-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1017.19~18.04.1').
  • OR linux-meta-snapdragon package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-oem package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-oem-osp1 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1010.11').
  • OR linux-oracle package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-oracle-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1007.12~18.04.1').
  • OR linux-raspi2 package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-raspi2-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1017.19~18.04.1').
  • OR linux-signed package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-signed-azure package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1014.14~18.04.1').
  • OR linux-signed-azure-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1007.8~18.04.1').
  • OR linux-signed-gcp package in bionic was vulnerable but has been fixed (note: '5.0.0-1020.20~18.04.1').
  • OR linux-signed-gcp-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1008.9~18.04.1').
  • OR linux-signed-gke-4.15 package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-signed-gke-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1011.11~18.04.1').
  • OR linux-signed-gke-5.3 package in bionic, is related to the CVE in some way and has been fixed (note: '5.3.0-1011.12~18.04.1').
  • OR linux-signed-hwe package in bionic was vulnerable but has been fixed (note: '5.0.0-23.24~18.04.1').
  • OR linux-signed-oem package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-signed-oem-osp1 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1010.11').
  • OR linux-signed-oracle package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • OR linux-signed-oracle-5.0 package in bionic, is related to the CVE in some way and has been fixed (note: '5.0.0-1007.12~18.04.1').
  • OR linux-snapdragon package in bionic is affected, but a decision has been made to defer addressing it (note: '2019-01-24').
  • BACK