Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DLA-1823-1 Critical: Linux Kernel Privilege Escalation

debian lts
Calendar Grey June 17, 2019
Dist Debian Esm H88
Significant Linux kernel patch for Debian tackles issues related to privilege escalation, service interruption, and potential data leak vulnerabilities.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

huangwen reported multiple buffer overflows in the Marvell wifi
(mwifiex) driver, which a local user could use to cause denial of
service or the execution of arbitrary code.

CVE-2019-5489

Daniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz, Ari
Trachtenberg, Jason Hennessey, Alex Ionescu, and Anders Fogh
discovered that local users could use the mincore() system call to
obtain sensitive information from other processes that access the
same memory-mapped file.

CVE-2019-11477

Jonathan Looney reported that a specially crafted sequence of TCP
selective acknowledgements (SACKs) allows a remotely triggerable
kernel panic.

CVE-2019-11478

Jonathan Looney reported that a specially crafted sequence of TCP
selective acknowledgements (SACKs) will fragment the TCP
retransmission queue, allowing an attacker to cause excessive
resource usage.

CVE-2019-11479

Jonathan Looney reported that an attacker could force the Linux

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: linux
Version: 3.16.68-2
CVE ID: CVE-2019-3846 CVE-2019-5489 CVE-2019-10126 CVE-2019-11477

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here