漏洞信息详情
Linux kernel 缓冲区错误漏洞
漏洞简介
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。
Linux kernel 4.14.8之前版本中的kernel/time/posix-timers.c文件存在安全漏洞,该漏洞源于timer_create系统调用的实现没有正确地验证sigevent->sigev_notify字段。攻击者可利用该漏洞读取任意的内核内存(越界读取)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3590
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3083
来源:MISC
链接:https://github.com/torvalds/linux/commit/cef31d9af908243421258f1df35a4a644604efbe
来源:UBUNTU
链接:https://usn.ubuntu.com/3742-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/3742-2/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3586
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3540
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3096
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3591
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3459
来源:SECTRACK
链接:http://www.securitytracker.com/id/1041414
来源:EXPLOIT-DB
链接:https://www.exploit-db.com/exploits/45175/
来源:BID
链接:https://www.securityfocus.com/bid/104909
来源:BID
链接:http://www.securityfocus.com/bid/104909
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2948
来源:MISC
链接:https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.8
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10883258
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10881053
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4318/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4318.3
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2341/
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10881424
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1800/
受影响实体
- Linux Linux_kernel:-<!--2000-1-1-->
- Linux Linux_kernel:1.2.0<!--2000-1-1-->
- Linux Linux_kernel:1.3.0<!--2000-1-1-->
- Linux Linux_kernel:2.0.1<!--2000-1-1-->
- Linux Linux_kernel:2.0.2<!--2000-1-1-->
补丁
- Linux kernel 安全漏洞的修复措施<!--2018-7-27-->
还没有评论,来说两句吧...