Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian DSA-4267-1 Critical Kernel Vulnerability: Privilege Escalation Risk

debian
Calendar Grey August 6, 2018
Debian Logo
Addressing CVE-2018-5390 and CVE-2018-13405 vulnerabilities within Debian Linux environments to bolster security.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation or denial of service

Summary

CVE-2018-5390

Juha-Matti Tilli discovered that a remote attacker can trigger the
worst case code paths for TCP stream reassembly with low rates of
specially crafted packets leading to remote denial of service.

CVE-2018-13405

Jann Horn discovered that the inode_init_owner function in
fs/inode.c in the Linux kernel allows local users to create files
with an unintended group ownership allowing attackers to escalate
privileges by making a plain file executable and SGID.

For the stable distribution (stretch), these problems have been fixed in
version 4.9.110-3+deb9u1. This update includes fixes for several
regressions in the latest point release.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2018-5390 CVE-2018-13405

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here