UBUNTU-CVE-2018-14625
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-14625
UBUNTU-CVE-2018-14625
Summary:
Details: A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.
References: https://ubuntu.com/security/CVE-2018-14625, https://syzkaller.appspot.com/bug?extid=bd391451452fb0b93039, https://lore.kernel.org/lkml/[email protected]/, https://lore.kernel.org/lkml/?q=%22syzbot%2Bbd391451452fb0b93039%40syzkaller.appspotmail.com%22, https://ubuntu.com/security/notices/USN-3871-1, https://ubuntu.com/security/notices/USN-3872-1, https://ubuntu.com/security/notices/USN-3871-3, https://ubuntu.com/security/notices/USN-3871-4, https://ubuntu.com/security/notices/USN-3878-1, https://ubuntu.com/security/notices/USN-3871-5, https://ubuntu.com/security/notices/USN-3878-2, https://www.cve.org/CVERecord?id=CVE-2018-14625
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/[email protected]~14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
