UBUNTU-CVE-2018-14678
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-14678
UBUNTU-CVE-2018-14678
Summary:
Details: An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.
References: https://ubuntu.com/security/CVE-2018-14678, https://xenbits.xen.org/xsa/advisory-274.html, https://git.kernel.org/linus/b3681dd548d06deb2e1573890829dff4b15abf46, https://ubuntu.com/security/notices/USN-3931-1, https://ubuntu.com/security/notices/USN-3931-2, https://www.cve.org/CVERecord?id=CVE-2018-14678
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
