UBUNTU-CVE-2018-1108
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1108
UBUNTU-CVE-2018-1108
Summary:
Details: kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
References: https://ubuntu.com/security/CVE-2018-1108, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=43838a23a05fbd13e47d750d3dfd77001536dd33, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dc12baacb95f205948f64dc936a47d89ee110117, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8ef35c866f8862df074a49a93b0309725812dea8, https://bugs.chromium.org/p/project-zero/issues/detail?id=1559, https://ubuntu.com/security/notices/USN-3752-1, https://ubuntu.com/security/notices/USN-3752-2, https://ubuntu.com/security/notices/USN-3752-3, https://www.cve.org/CVERecord?id=CVE-2018-1108
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
