Kernel Live Patch Security Notice LSN-0043-1

Discussion in 'News Aggregator' started by Packet Storm, 11 Sep 2018.

  1. Packet Storm

    Packet Storm Guest

    Piotr Gabriel Kosinski and Daniel Shapira discovered a stack-based buffer overflow in the CDROM driver implementation of the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Jann Horn discovered that the ext4 filesystem implementation in the Linux kernel did not properly keep xattr information consistent in some situations. An attacker could use this to construct a malicious ext4 image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. Various other issues have also been addressed.

    Continue reading...
     

Share This Page

Loading...