USN-3903-2

Source
https://ubuntu.com/security/notices/USN-3903-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3903-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-3903-2
Related
Published
2019-03-06T19:33:05.557617Z
Modified
2019-03-06T19:33:05.557617Z
Summary
linux-hwe, linux-azure vulnerabilities
Details

USN-3903-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.10. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 18.10 for Ubuntu 18.04 LTS.

Jason Wang discovered that the vhost net driver in the Linux kernel contained an out of bounds write vulnerability. An attacker in a guest virtual machine could use this to cause a denial of service (host system crash) or possibly execute arbitrary code in the host kernel. (CVE-2018-16880)

Jann Horn discovered that the userfaultd implementation in the Linux kernel did not properly restrict access to certain ioctls. A local attacker could use this possibly to modify files. (CVE-2018-18397)

Jann Horn discovered a race condition in the fork() system call in the Linux kernel. A local attacker could use this to gain access to services that cache authorizations. (CVE-2019-6133)

References

Affected packages

Ubuntu:18.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-1013.13~18.04.1

Affected versions

4.*

4.15.0-1002.2
4.15.0-1003.3
4.15.0-1004.4
4.15.0-1008.8
4.15.0-1009.9
4.15.0-1012.12
4.15.0-1013.13
4.15.0-1014.14
4.15.0-1018.18
4.15.0-1019.19
4.15.0-1021.21
4.15.0-1022.23
4.15.0-1023.24
4.15.0-1025.26
4.15.0-1028.29
4.15.0-1030.31
4.15.0-1031.32
4.15.0-1032.33
4.15.0-1035.36
4.15.0-1036.38
4.15.0-1037.39
4.18.0-1011.11~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-azure-cloud-tools-4.18.0-1013"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-azure-headers-4.18.0-1013"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-azure-tools-4.18.0-1013"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-1013-azure"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-cloud-tools-4.18.0-1013-azure"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-headers-4.18.0-1013-azure"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-1013-azure"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-1013-azure-dbgsym"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-modules-4.18.0-1013-azure"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-modules-extra-4.18.0-1013-azure"
        },
        {
            "binary_version": "4.18.0-1013.13~18.04.1",
            "binary_name": "linux-tools-4.18.0-1013-azure"
        }
    ]
}

Ubuntu:18.04:LTS / linux-hwe

Package

Name
linux-hwe
Purl
pkg:deb/ubuntu/linux-hwe?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-16.17~18.04.1

Affected versions

4.*

4.18.0-13.14~18.04.1
4.18.0-14.15~18.04.1
4.18.0-15.16~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "block-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "block-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "block-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "crypto-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "crypto-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "crypto-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "dasd-extra-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "dasd-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fat-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fat-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fat-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fb-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "firewire-core-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "floppy-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fs-core-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fs-core-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fs-core-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fs-secondary-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fs-secondary-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "fs-secondary-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "input-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "input-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "input-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "ipmi-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "ipmi-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "ipmi-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "kernel-image-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "kernel-image-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "kernel-image-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-16-generic-lpae"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-16-lowlatency"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-buildinfo-4.18.0-16-snapdragon"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-cloud-tools-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-cloud-tools-4.18.0-16-lowlatency"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-headers-4.18.0-16"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-headers-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-headers-4.18.0-16-generic-lpae"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-headers-4.18.0-16-lowlatency"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-headers-4.18.0-16-snapdragon"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-hwe-cloud-tools-4.18.0-16"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-hwe-tools-4.18.0-16"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-hwe-udebs-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-hwe-udebs-generic-lpae"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-hwe-udebs-snapdragon"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-generic-dbgsym"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-generic-lpae"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-generic-lpae-dbgsym"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-lowlatency"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-lowlatency-dbgsym"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-snapdragon"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-4.18.0-16-snapdragon-dbgsym"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-16-generic-dbgsym"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-16-lowlatency"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-image-unsigned-4.18.0-16-lowlatency-dbgsym"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-modules-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-modules-4.18.0-16-generic-lpae"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-modules-4.18.0-16-lowlatency"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-modules-4.18.0-16-snapdragon"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-modules-extra-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-source-4.18.0"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-tools-4.18.0-16-generic"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-tools-4.18.0-16-generic-lpae"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-tools-4.18.0-16-lowlatency"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "linux-tools-4.18.0-16-snapdragon"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "md-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "md-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "md-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "message-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "message-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "mouse-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "mouse-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "mouse-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "multipath-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "multipath-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "multipath-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nfs-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nfs-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nfs-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-pcmcia-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-shared-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-shared-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-shared-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-usb-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-usb-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "nic-usb-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "parport-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "parport-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "parport-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "pata-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "pcmcia-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "pcmcia-storage-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "plip-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "plip-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "plip-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "ppp-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "ppp-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "ppp-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "sata-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "sata-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "sata-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "scsi-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "scsi-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "scsi-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "serial-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "storage-core-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "storage-core-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "storage-core-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "usb-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "usb-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "usb-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "virtio-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "virtio-modules-4.18.0-16-snapdragon-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "vlan-modules-4.18.0-16-generic-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "vlan-modules-4.18.0-16-generic-lpae-di"
        },
        {
            "binary_version": "4.18.0-16.17~18.04.1",
            "binary_name": "vlan-modules-4.18.0-16-snapdragon-di"
        }
    ]
}