ALINUX2-SA-2019%3A0014
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-9162: In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper. CVE-2019-8980: A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures. CVE-2019-9213: In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | kernel |
Timeline
- Mar 26, 2019 CVE Published
- Mar 26, 2019 CVE Updated
References
- ALINUX2-SA-2019:0014: cloud-kernel bugfix, enhancement and security update (Important) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9162 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8980 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9213 advisory