USN-3872-1

Source
https://ubuntu.com/security/notices/USN-3872-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3872-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-3872-1
Related
Published
2019-01-29T02:54:09.290168Z
Modified
2019-01-29T02:54:09.290168Z
Summary
linux-hwe vulnerabilities
Details

It was discovered that a race condition existed in the vsock address family implementation of the Linux kernel that could lead to a use-after-free condition. A local attacker in a guest virtual machine could use this to expose sensitive information (host machine kernel memory). (CVE-2018-14625)

Cfir Cohen discovered that a use-after-free vulnerability existed in the KVM implementation of the Linux kernel, when handling interrupts in environments where nested virtualization is in use (nested KVM virtualization is not enabled by default in Ubuntu kernels). A local attacker in a guest VM could possibly use this to gain administrative privileges in a host machine. (CVE-2018-16882)

Wei Wu discovered that the KVM implementation in the Linux kernel did not properly ensure that ioapics were initialized. A local attacker could use this to cause a denial of service (system crash). (CVE-2018-19407)

It was discovered that the crypto subsystem of the Linux kernel leaked uninitialized memory to user space in some situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2018-19854)

References

Affected packages

Ubuntu:18.04:LTS / linux-hwe

Package

Name
linux-hwe
Purl
pkg:deb/ubuntu/linux-hwe?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-14.15~18.04.1

Affected versions

4.*

4.18.0-13.14~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "block-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "block-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "block-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "crypto-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "crypto-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "crypto-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "dasd-extra-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "dasd-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fat-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fat-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fat-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fb-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "firewire-core-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "floppy-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fs-core-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fs-core-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fs-core-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fs-secondary-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fs-secondary-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "fs-secondary-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "input-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "input-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "input-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "ipmi-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "ipmi-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "ipmi-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "kernel-image-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "kernel-image-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "kernel-image-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-14-generic-lpae"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-14-lowlatency"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-14-snapdragon"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-cloud-tools-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-cloud-tools-4.18.0-14-lowlatency"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-headers-4.18.0-14"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-headers-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-headers-4.18.0-14-generic-lpae"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-headers-4.18.0-14-lowlatency"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-headers-4.18.0-14-snapdragon"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-hwe-cloud-tools-4.18.0-14"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-hwe-tools-4.18.0-14"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-hwe-udebs-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-hwe-udebs-generic-lpae"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-hwe-udebs-snapdragon"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-generic-dbgsym"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-generic-lpae"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-generic-lpae-dbgsym"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-lowlatency"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-lowlatency-dbgsym"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-snapdragon"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-4.18.0-14-snapdragon-dbgsym"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-14-generic-dbgsym"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-14-lowlatency"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-14-lowlatency-dbgsym"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-modules-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-modules-4.18.0-14-generic-lpae"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-modules-4.18.0-14-lowlatency"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-modules-4.18.0-14-snapdragon"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-modules-extra-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-source-4.18.0"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-tools-4.18.0-14-generic"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-tools-4.18.0-14-generic-lpae"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-tools-4.18.0-14-lowlatency"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "linux-tools-4.18.0-14-snapdragon"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "md-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "md-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "md-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "message-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "message-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "mouse-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "mouse-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "mouse-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "multipath-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "multipath-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "multipath-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nfs-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nfs-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nfs-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-pcmcia-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-shared-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-shared-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-shared-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-usb-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-usb-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "nic-usb-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "parport-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "parport-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "parport-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "pata-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "pcmcia-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "pcmcia-storage-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "plip-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "plip-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "plip-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "ppp-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "ppp-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "ppp-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "sata-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "sata-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "sata-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "scsi-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "scsi-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "scsi-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "serial-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "storage-core-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "storage-core-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "storage-core-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "usb-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "usb-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "usb-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "virtio-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "virtio-modules-4.18.0-14-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "vlan-modules-4.18.0-14-generic-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "vlan-modules-4.18.0-14-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-14.15~18.04.1",
            "binary_name": "vlan-modules-4.18.0-14-snapdragon-di"
        }
    ]
}