Ubuntu Security Notice USN-3872-1

Discussion in 'News Aggregator' started by Packet Storm, 29 Jan 2019.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3872-1 - It was discovered that a race condition existed in the vsock address family implementation of the Linux kernel that could lead to a use-after-free condition. A local attacker in a guest virtual machine could use this to expose sensitive information. Cfir Cohen discovered that a use-after-free vulnerability existed in the KVM implementation of the Linux kernel, when handling interrupts in environments where nested virtualization is in use. A local attacker in a guest VM could possibly use this to gain administrative privileges in a host machine. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...