UBUNTU-CVE-2018-1118
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1118
UBUNTU-CVE-2018-1118
Summary:
Details: Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
References: https://ubuntu.com/security/CVE-2018-1118, https://lkml.org/lkml/2018/4/27/833, https://lkml.org/lkml/2018/5/29/1324, https://ubuntu.com/security/notices/USN-3762-1, https://ubuntu.com/security/notices/USN-3762-2, https://www.cve.org/CVERecord?id=CVE-2018-1118
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
