Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (18)
📋 Description
CVE-2012-6701 — kernel: AIO interface didn't use rw_verify_area() for checking mandatory locking on files and size of access CVE-2015-8830 — kernel: AIO write triggers integer overflow in some protocols CVE-2016-8650 — kernel: Null pointer dereference via keyctl CVE-2017-2671 — kernel: ping socket / AF_LLC connect() sin_family race CVE-2017-6001 — kernel: Race condition between multiple sys_perf_event_open() calls CVE-2017-7308 — kernel: net/packet: overflow in check for priv area size CVE-2017-7616 — kernel: Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c CVE-2017-7889 — kernel: mm subsystem does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism CVE-2017-8890 — kernel: Double free in the inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c CVE-2017-9075 — kernel: net: sctp_v6_create_accept_sk function mishandles inheritance CVE-2017-9076 — kernel: net: IPv6 DCCP implementation mishandles inheritance CVE-2017-9077 — kernel: net: tcp_v6_syn_recv_sock function mishandles inheritance CVE-2017-12190 — kernel: memory leak when merging buffers in SCSI IO vectors CVE-2017-15121 — kernel: vfs: BUG in truncate_inode_pages_range() and fuse client CVE-2017-18203 — kernel: Race condition in drivers/md/dm.c:dm_get_from_kobject() allows local users to cause a denial of service CVE-2018-1130 — kernel: a null pointer dereference in net/dccp/output.c:dccp_write_xmit() leads to a system crash CVE-2018-3639 — hw: cpu: speculative store bypass CVE-2018-5803 — kernel: Missing length check of payload in net/sctp/sm_make_chunk.c:_sctp_make_chunk() function allows denial of service
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2018:1854
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/ssbd
- externalhttps://access.redhat.com/documentation/en-US/red_hat_enterprise_linux/6/html/6.10_release_notes/index.html
- externalhttps://access.redhat.com/documentation/en-US/red_hat_enterprise_linux/6/html/6.10_technical_notes/index.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=869942
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1314275
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1314288
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1395187
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1422825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1436649
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1437404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1441088
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1444493
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1448170
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1450972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1452688
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1452691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1452744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1495089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1497152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1520893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1550811
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1551051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1560494
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1566890
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1576419
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_1854.json