RHSA-2018:2384HighCVSS 7.5
Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (7)
📋 Description
CVE-2017-13215 — kernel: crypto: privilege escalation in skcipher_recvmsg function CVE-2018-3620 — Kernel: hw: cpu: L1 terminal fault (L1TF) CVE-2018-3646 — Kernel: hw: cpu: L1 terminal fault (L1TF) CVE-2018-3693 — Kernel: speculative bounds check bypass store CVE-2018-5390 — kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack) CVE-2018-7566 — kernel: race condition in snd_seq_write() may lead to UAF or OOB-access CVE-2018-10675 — kernel: mm: use-after-free in do_get_mempolicy function allows local DoS or other unspecified impact
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2018:2384
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/L1TF
- externalhttps://access.redhat.com/articles/3527791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1535173
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1550142
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1575065
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1581650
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1585005
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601704
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2384.json