漏洞信息详情
Linux kernel 访问控制错误漏洞
漏洞简介
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。
Linux kernel 4.19.7之前版本中userfaultfd的实现存在安全漏洞,该漏洞源于程序没有正确地处理对UFFDIO_ ioctl调用的访问控制。本地攻击者可利用该漏洞写入数据。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.7
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.87
参考网址
来源:UBUNTU
链接:https://usn.ubuntu.com/3901-1/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0831
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0324
来源:REDHAT
链接:https://access.redhat.com/errata/RHBA-2019:0327
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0202
来源:UBUNTU
链接:https://usn.ubuntu.com/3903-2/
来源:UBUNTU
链接:https://usn.ubuntu.com/3901-2/
来源:UBUNTU
链接:https://usn.ubuntu.com/3903-1/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0163
来源:MISC
链接:https://bugs.chromium.org/p/project-zero/issues/detail?id=1700
来源:MISC
链接:http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=29ec90660d68bbdd69507c1c8b4e33aa299278b1
来源:MISC
链接:https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.7
来源:MISC
链接:https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.87
来源:MISC
链接:https://github.com/torvalds/linux/commit/29ec90660d68bbdd69507c1c8b4e33aa299278b1
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/3901-1/
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/3903-1/
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:0831
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76538
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152597/Red-Hat-Security-Advisory-2019-0831-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76642
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75530
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/151997/Ubuntu-Security-Notice-USN-3903-2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79578
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/151987/Ubuntu-Security-Notice-USN-3901-2.html
受影响实体
暂无
补丁
- Linux kernel 安全漏洞的修复措施<!--2018-12-13-->
还没有评论,来说两句吧...