UBUNTU-CVE-2018-17972
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-17972
UBUNTU-CVE-2018-17972
Summary:
Details: An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.
References: https://ubuntu.com/security/CVE-2018-17972, https://marc.info/?l=linux-fsdevel&m=153806242024956&w=2, https://lore.kernel.org/patchwork/patch/992734/, https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=680d86b71ff9779f770758eaf9cadee98465223c, https://ubuntu.com/security/notices/USN-3821-1, https://ubuntu.com/security/notices/USN-3821-2, https://ubuntu.com/security/notices/USN-3832-1, https://ubuntu.com/security/notices/USN-3835-1, https://ubuntu.com/security/notices/USN-3871-1, https://ubuntu.com/security/notices/USN-3871-3, https://ubuntu.com/security/notices/USN-3871-4, https://ubuntu.com/security/notices/USN-3880-1, https://ubuntu.com/security/notices/USN-3880-2, https://ubuntu.com/security/notices/USN-3871-5, https://www.cve.org/CVERecord?id=CVE-2018-17972
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
