UBUNTU-CVE-2017-16994
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16994
UBUNTU-CVE-2017-16994
Summary:
Details: The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.
References: https://ubuntu.com/security/CVE-2017-16994, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=373c4557d2aa362702c4c2d41288fb1e54990b7c, http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.2, https://bugs.chromium.org/p/project-zero/issues/detail?id=1431, https://github.com/torvalds/linux/commit/373c4557d2aa362702c4c2d41288fb1e54990b7c, https://ubuntu.com/security/notices/USN-3617-1, https://ubuntu.com/security/notices/USN-3617-2, https://ubuntu.com/security/notices/USN-3617-3, https://ubuntu.com/security/notices/USN-3619-1, https://ubuntu.com/security/notices/USN-3619-2, https://ubuntu.com/security/notices/USN-3632-1, https://www.cve.org/CVERecord?id=CVE-2017-16994
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
