It was discovered that the Linux kernel did not properly initialize a Wake- on-Lan data structure. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2014-9900)
It was discovered that the Linux kernel did not properly restrict access to /proc/iomem. A local attacker could use this to expose sensitive information. (CVE-2015-8944)
Alexander Potapenko discovered a race condition in the Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2017-1000380)
Li Qiang discovered that the DRM driver for VMware Virtual GPUs in the Linux kernel did not properly validate some ioctl arguments. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-7346)
Jann Horn discovered that bpf in Linux kernel does not restrict the output of the printbpfinsn function. A local attacker could use this to obtain sensitive address information. (CVE-2017-9150)
Murray McAllister discovered that the DRM driver for VMware Virtual GPUs in the Linux kernel did not properly initialize memory. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2017-9605)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "linux-aws-cloud-tools-4.4.0-1026",
"binary_version": "4.4.0-1026.35"
},
{
"binary_name": "linux-aws-headers-4.4.0-1026",
"binary_version": "4.4.0-1026.35"
},
{
"binary_name": "linux-aws-tools-4.4.0-1026",
"binary_version": "4.4.0-1026.35"
},
{
"binary_name": "linux-cloud-tools-4.4.0-1026-aws",
"binary_version": "4.4.0-1026.35"
},
{
"binary_name": "linux-headers-4.4.0-1026-aws",
"binary_version": "4.4.0-1026.35"
},
{
"binary_name": "linux-image-4.4.0-1026-aws",
"binary_version": "4.4.0-1026.35"
},
{
"binary_name": "linux-tools-4.4.0-1026-aws",
"binary_version": "4.4.0-1026.35"
}
]
}
{
"ecosystem": "Ubuntu:16.04:LTS",
"cves": [
{
"id": "CVE-2014-9900",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2015-8944",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "low"
}
]
},
{
"id": "CVE-2017-7346",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2017-9150",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2017-9605",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "low"
}
]
},
{
"id": "CVE-2017-1000380",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "low"
}
]
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "linux-cloud-tools-4.4.0-1022-gke",
"binary_version": "4.4.0-1022.22"
},
{
"binary_name": "linux-gke-cloud-tools-4.4.0-1022",
"binary_version": "4.4.0-1022.22"
},
{
"binary_name": "linux-gke-headers-4.4.0-1022",
"binary_version": "4.4.0-1022.22"
},
{
"binary_name": "linux-gke-tools-4.4.0-1022",
"binary_version": "4.4.0-1022.22"
},
{
"binary_name": "linux-headers-4.4.0-1022-gke",
"binary_version": "4.4.0-1022.22"
},
{
"binary_name": "linux-image-4.4.0-1022-gke",
"binary_version": "4.4.0-1022.22"
},
{
"binary_name": "linux-image-extra-4.4.0-1022-gke",
"binary_version": "4.4.0-1022.22"
},
{
"binary_name": "linux-tools-4.4.0-1022-gke",
"binary_version": "4.4.0-1022.22"
}
]
}
{
"ecosystem": "Ubuntu:16.04:LTS",
"cves": [
{
"id": "CVE-2014-9900",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2015-8944",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "low"
}
]
},
{
"id": "CVE-2017-7346",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2017-9150",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2017-9605",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "low"
}
]
},
{
"id": "CVE-2017-1000380",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "low"
}
]
}
]
}