Revision Date: | 2018-08-30 | Version: | 1 | Title: | CVE-2018-14619 on Ubuntu 16.04 LTS (xenial) - medium. | Description: | A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_ctx was freed instead of when the aead_tfm was freed. This can cause the null skcipher to be freed while it is still in use leading to a local user being able to crash the system or possibly escalate privileges.
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2018-14619
| Platform(s): | Ubuntu 16.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 16.04 LTS (xenial) is installed. AND Package Information
NOT While related to the CVE in some way, the 'linux' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-aws' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-azure' package in xenial is not affected (note: '4.15.0-1013.13~16.04.2').
OR NOT While related to the CVE in some way, the 'linux-azure-edge' package in xenial is not affected (note: '4.15.0-1002.2').
OR NOT While related to the CVE in some way, the 'linux-euclid' package in xenial is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-gcp' package in xenial is not affected (note: '4.15.0-1014.14~16.04.1').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'end-of-life').
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'end-of-life').
OR NOT While related to the CVE in some way, the 'linux-hwe' package in xenial is not affected (note: '4.15.0-24.26~16.04.1').
OR NOT While related to the CVE in some way, the 'linux-hwe-edge' package in xenial is not affected (note: '4.15.0-24.26~16.04.1').
OR NOT While related to the CVE in some way, the 'linux-kvm' package in xenial is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-oem' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-raspi2' package in xenial is not affected.
OR NOT While related to the CVE in some way, the 'linux-snapdragon' package in xenial is not affected.
|
|