Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia 6: MGASA-2018-0373 Critical: Kernel Memory Leak and DoS Fix

mageia
Calendar Grey September 14, 2018
Dist Mageia Esm H88
Linux kernel upgrade addresses vulnerabilities such as L1TF and CVE-2018-6554, improving system reliability for Mageia users.
This kernel update is based on the upstream 4.14.69 and adds additional fixes for the L1TF and Spectre security issues

Summary

This kernel update is based on the upstream 4.14.69 and adds additional fixes for the L1TF and Spectre security issues. It also fixes atleast the following security issues:
Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket (CVE-2018-6554).
The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket (CVE-2018-6554).
Other fixes in this update: * WireGuard has been updated to 0.0.20180904 * all SPI_INTEL_SPI config options have been disable to prevent a potential bios corrupting bug (mga#23560)
For other changes in this update, see the referenced changelogs.

References

- https://bugs.mageia.org/show_bug.cgi?id=23543

- https://bugs.mageia.org/show_bug.cgi?id=23560

- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.66

- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.67

- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.68

- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.69

- https://www.cve.org/CVERecord?id=CVE-2018-6554

- https://www.cve.org/CVERecord?id=CVE-2018-6555

Resolution

SRPMS

- 6/core/kernel-4.14.69-1.mga6

- 6/core/kernel-userspace-headers-4.14.69-1.mga6

- 6/core/kmod-vboxadditions-5.2.18-3.mga6

- 6/core/kmod-virtualbox-5.2.18-3.mga6

- 6/core/kmod-xtables-addons-2.13-63.mga6

- 6/core/wireguard-tools-0.0.20180904-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 14 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0373.html
Type: security
CVE: CVE-2018-6554, CVE-2018-6555

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here