Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian 8: DLA-1824-1 Critical: Linux 4.9 Privilege Escalation Threats

debian lts
Calendar Grey June 18, 2019
Dist Debian Esm H88
Package : linux-4.9 Version : 4.9.168-1+deb9u3~deb8u1 CVE ID : CVE-2019-3846 CVE-2019-5489 CVE-2019-
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

huangwen reported multiple buffer overflows in the Marvell wifi
(mwifiex) driver, which a local user could use to cause denial of
service or the execution of arbitrary code.

CVE-2019-5489

Daniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz, Ari
Trachtenberg, Jason Hennessey, Alex Ionescu, and Anders Fogh
discovered that local users could use the mincore() system call to
obtain sensitive information from other processes that access the
same memory-mapped file.

CVE-2019-9500, CVE-2019-9503

Hugues Anguelkov discovered a buffer overflow and missing access
validation in the Broadcom FullMAC wifi driver (brcmfmac), which a
attacker on the same wifi network could use to cause denial of
service or the execution of arbitrary code.

CVE-2019-11477

Jonathan Looney reported that a specially crafted sequence of TCP
selective acknowledgements (SACKs) allows a remotely triggerable
kernel panic.

CVE-2019-11478

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: linux-4.9
Version: 4.9.168-1+deb9u3~deb8u1
CVE ID: CVE-2019-3846 CVE-2019-5489 CVE-2019-9500 CVE-2019-9503
Debian Bug: 928989

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here