漏洞信息详情
Linux kernel 权限许可和访问控制问题漏洞
漏洞简介
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。
Linux kernel 4.17.4及之前版本中的fs/inode.c文件的‘inode_init_owner’函数存在权限许可和访问控制问题漏洞。攻击者可利用该漏洞获取提升的权限。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0fa3ecd87848c9c93c2c828ef4c3a8ca36ce46c7
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3083
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0717
来源:MISC
链接:http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0fa3ecd87848c9c93c2c828ef4c3a8ca36ce46c7
来源:BID
链接:http://www.securityfocus.com/bid/106503
来源:BID
链接:https://www.securityfocus.com/bid/106503
来源:CONFIRM
链接:https://support.f5.com/csp/article/K00854051
来源:CONFIRM
链接:https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=0b3369840cd61c23e2b9241093737b4c395cb406
来源:MISC
链接:https://github.com/torvalds/linux/commit/0fa3ecd87848c9c93c2c828ef4c3a8ca36ce46c7
来源:UBUNTU
链接:https://usn.ubuntu.com/3752-3/
来源:UBUNTU
链接:https://usn.ubuntu.com/3753-2/
来源:UBUNTU
链接:https://usn.ubuntu.com/3754-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/3752-1/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:4164
来源:EXPLOIT-DB
链接:https://www.exploit-db.com/exploits/45033/
来源:source.android.com
链接:https://source.android.com/security/bulletin/2019-01-01.html
来源:www.android.com
链接:http://www.android.com/
来源:www.oracle.com
链接:https://www.oracle.com/technetwork/topics/security/linuxbulletinapr2019-5461367.html
来源:git.kernel.org
链接:https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0fa3ecd87848c9c93c2c828ef4c3a8ca36ce46c7
来源:git.kernel.org
链接:https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c37e9e013469521d9adb932d17a1795c139b36db
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2018-13405
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2018-10882
来源:bugzilla.kernel.org
链接:https://bugzilla.kernel.org/show_bug.cgi?id=200069
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1599161
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1596842
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2948
来源:MISC
链接:http://openwall.com/lists/oss-security/2018/07/13/2
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2018/08/msg00014.html
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2566
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:3096
来源:UBUNTU
链接:https://usn.ubuntu.com/3752-2/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2476
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2696
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:4159
来源:UBUNTU
链接:https://usn.ubuntu.com/3753-1/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2730
来源:DEBIAN
链接:https://www.debian.org/security/2018/dsa-4266
来源:MISC
链接:https://twitter.com/grsecurity/status/1015082951204327425
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4168
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4164
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4159
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4154
来源:support.f5.com
链接:https://support.f5.com/csp/article/K00854051
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10883258
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10881053
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:0717
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4608/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1636.4/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3968
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152448/Red-Hat-Security-Advisory-2019-0717-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2341/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3938
来源:www.securityfocus.com
链接:http://www.securityfocus.com/bid/106503
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/106503
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80590
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155607/Red-Hat-Security-Advisory-2019-4159-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3872
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/78734
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10881424
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1800/
受影响实体
- Linux Linux_kernel:4.17.4<!--2000-1-1-->
补丁
- Linux kernel 安全漏洞的修复措施<!--2018-7-9-->
还没有评论,来说两句吧...