AWS-2018-018
Linux Kernel Updates to address SegmentSmack & FragmentSmack
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Linux Kernel Updates to address SegmentSmack & FragmentSmack
ALAS-2018-1058: kernel (critical)
CVEs:CVE-2018-3615CVE-2018-3620CVE-2018-3646CVE-2018-5391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2018-1049: kernel (critical)
CVEs:CVE-2018-13405CVE-2018-5390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2018-1062: httpd24 (medium)
CVEs:CVE-2018-8011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| httpd24 | affected | Amazon | httpd24 | — |
ALAS-2018-1056: tomcat8 (important)
CVEs:CVE-2018-1336CVE-2018-8014CVE-2018-8034CVE-2018-8037
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tomcat8 | affected | Amazon | tomcat8 | — |
ALAS-2018-1055: tomcat7, tomcat80 (important)
CVEs:CVE-2018-1336CVE-2018-8014CVE-2018-8034
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tomcat7, tomcat80 | affected | Amazon | tomcat7, tomcat80 | — |
ALAS-2018-1070: mysql57 (medium)
CVEs:CVE-2018-0739CVE-2018-2767CVE-2018-3054CVE-2018-3056CVE-2018-3058CVE-2018-3060CVE-2018-3061CVE-2018-3062CVE-2018-3064CVE-2018-3065CVE-2018-3066CVE-2018-3070CVE-2018-3071CVE-2018-3077CVE-2018-3081
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mysql57 | affected | Amazon | mysql57 | — |
ALAS-2018-1069: mysql56 (medium)
CVEs:CVE-2018-0739CVE-2018-2767CVE-2018-3058CVE-2018-3062CVE-2018-3064CVE-2018-3066CVE-2018-3070CVE-2018-3081
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mysql56 | affected | Amazon | mysql56 | — |
ALAS-2018-1065: openssl (medium)
CVEs:CVE-2018-0733CVE-2018-0739
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openssl | affected | Amazon | openssl | — |
ALAS-2018-1067: php72 (medium)
CVEs:CVE-2018-12882CVE-2018-14851CVE-2018-14883
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php72 | affected | Amazon | php72 | — |
ALAS-2018-1066: php56, php70, php71 (low)
CVEs:CVE-2018-14851CVE-2018-14883
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php56, php70, php71 | affected | Amazon | php56, php70, php71 | — |
L1 Terminal Fault Speculative Execution Issue
ALAS-2018-1057: yum-utils (important)
CVEs:CVE-2018-10897
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| yum-utils | affected | Amazon | yum-utils | — |
ALAS-2018-1064: java-1.7.0-openjdk (medium)
CVEs:CVE-2018-2952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.7.0-openjdk | affected | Amazon | java-1.7.0-openjdk | — |
ALAS-2018-1054: java-1.8.0-openjdk (medium)
CVEs:CVE-2018-2952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.8.0-openjdk | affected | Amazon | java-1.8.0-openjdk | — |
ALAS-2018-1068: mysql55 (medium)
CVEs:CVE-2018-2767CVE-2018-3058CVE-2018-3063CVE-2018-3066CVE-2018-3070CVE-2018-3081
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mysql55 | affected | Amazon | mysql55 | — |
ALAS-2018-1048: kernel (low)
CVEs:CVE-2018-13093CVE-2018-13094
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.