VDB

GCVE-VVD-MAGEIA-2018-187

GCVE-VVD-MAGEIA-2018-187
Advisory Published
Vulnetix · Advisory published December 26, 2018
This kernel update is based on the upstream 4.14.30 and fixes at least the following security issues: The KPTI mitigation for Meltdown (CVE-2017-5754) on 32bit x86 has been updated to revision 4. A flaw was found in the Linux kernel implementation of 32 bit syscall interface for bridging allowing a privileged user to arbitrarily write to a limited range of kernel memory. This flaw can be exploited not only by a system's privileged user (a real "root" user), but also by an attacker who is a privileged user (a "root" user) in a user+network namespace (CVE-2018-1068). A race condition vulnerability exists in the sound system, that can lead to a deadlock and denial of service condition (CVE-2018-1000004). Other changes in this update: 3rdparty rtl8812au driver has been updated to v5.2.20 (mga#22808) and adds fixes for KRACK security issue. For other upstream fixes in this update, read the referenced changelogs.

Affected Products

VendorProductVersionsPlatforms
Mageiakernel-userspace-headers0 (affected), 4.14.30-3.mga6 (unaffected), 0 (affected), 4.14.30-3.mga6 (unaffected)
Mageiakernel0 (affected), 4.14.30-3.mga6 (unaffected), 0 (affected), 4.14.30-3.mga6 (unaffected)
Mageiakmod-virtualbox0 (affected), 5.2.8-6.mga6 (unaffected), 0 (affected), 5.2.8-6.mga6 (unaffected)
Mageiakmod-xtables-addons0 (affected), 2.13-26.mga6 (unaffected), 0 (affected), 2.13-26.mga6 (unaffected)
Mageiaredis0 (affected), 4.0.12-1.mga6 (unaffected)
Mageiakmod-vboxadditions0 (affected), 5.2.8-6.mga6 (unaffected), 0 (affected), 5.2.8-6.mga6 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›