Revision Date: | 2018-01-14 | Version: | 1 | Title: | CVE-2017-15126 on Ubuntu 16.04 LTS (xenial) - medium. | Description: | A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly can lead to a situation where a fork event will be removed from an already freed list of events with userfaultfd_ctx_put().
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2017-15126
| Platform(s): | Ubuntu 16.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 16.04 LTS (xenial) is installed. AND Package Information
NOT While related to the CVE in some way, the 'linux' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-aws' package in xenial is not affected.
OR The 'linux-azure' package in xenial was vulnerable but has been fixed (note: '4.13.0-1005.7').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'was needed ESM criteria').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-gcp' package in xenial is not affected (note: '4.13.0-1002.5').
OR NOT While related to the CVE in some way, the 'linux-gke' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-goldfish' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-hwe' package in xenial is not affected (note: '4.13.0-26.29~16.04.2').
OR NOT While related to the CVE in some way, the 'linux-hwe-edge' package in xenial is not affected (note: '4.13.0-26.29~16.04.2').
OR NOT While related to the CVE in some way, the 'linux-kvm' package in xenial is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-oem' package in xenial is not affected (note: '4.13.0-1008.9').
OR NOT While related to the CVE in some way, the 'linux-raspi2' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-snapdragon' package in xenial is not affected.
|
|