漏洞信息详情
Linux kernel 安全漏洞
漏洞简介
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。
Linux kernel 4.6.3及之前版本的arch/x86/kvm/vmx.c文件中存在安全漏洞,该漏洞源于程序没有正确处理APICv on/off状态。虚拟机端攻击者可借助x2APIC模式利用该漏洞获取主机操作系统的直接的APIC MSR访问权限,造成拒绝服务(主机操作系统崩溃),或执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=38327424b40bcebe2de92d07312c89360ac9229a
参考网址
来源:CONFIRM
链接:https://github.com/torvalds/linux/commit/38327424b40bcebe2de92d07312c89360ac9229a
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-1657.html
来源:DEBIAN
链接:https://www.debian.org/security/2016/dsa-3607
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-2076.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-2006.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00014.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00023.html
来源:CONFIRM
链接:http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=38327424b40bcebe2de92d07312c89360ac9229a
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3056-1
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3054-1
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3052-1
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-1541.html
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3050-1
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00012.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-1539.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-2074.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html
来源:CONFIRM
链接:http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3049-1
来源:DEBIAN
链接:http://www.debian.org/security/2016/dsa-3607
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00017.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3057-1
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3055-1
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3053-1
来源:UBUNTU
链接:http://www.ubuntu.com/usn/USN-3051-1
来源:CONFIRM
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1341716
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-2128.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-2133.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2016-1532.html
来源:CONFIRM
链接:http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00013.html
来源:CONFIRM
链接:http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00027.html
来源:SECTRACK
链接:http://www.securitytracker.com/id/1036763
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2016/06/15/11
受影响实体
- Redhat Enterprise_linux_workstation:7.0<!--2000-1-1-->
- Redhat Enterprise_linux_server_eus:7.2<!--2000-1-1-->
- Redhat Enterprise_linux_server_aus:7.2<!--2000-1-1-->
- Redhat Enterprise_linux_server:7.0<!--2000-1-1-->
- Redhat Enterprise_linux_hpc_node_eus:7.0<!--2000-1-1-->
补丁
- Linux kernel 安全漏洞的修复措施<!--2016-6-16-->
还没有评论,来说两句吧...