Kernel Live Patch Security Notice LSN-0037-1

Discussion in 'News Aggregator' started by Packet Storm, 8 May 2018.

  1. Packet Storm

    Packet Storm Guest

    Jann Horn discovered that the Berkeley Packet Filter (BPF) implementation in the Linux kernel improperly performed sign extension in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. It was discovered that a race condition leading to a use-after-free vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...