The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
http://www.securityfocus.com/bid/104093
https://access.redhat.com/errata/RHSA-2018:2164
https://access.redhat.com/errata/RHSA-2018:2384
https://access.redhat.com/errata/RHSA-2018:2395
https://access.redhat.com/errata/RHSA-2018:2785
https://access.redhat.com/errata/RHSA-2018:2791
https://access.redhat.com/errata/RHSA-2018:2924
https://access.redhat.com/errata/RHSA-2018:2925
https://access.redhat.com/errata/RHSA-2018:2933
https://access.redhat.com/errata/RHSA-2018:3540
https://access.redhat.com/errata/RHSA-2018:3586
https://access.redhat.com/errata/RHSA-2018:3590
https://github.com/torvalds/linux/commit/73223e4e2e3867ebf033a5a8eb2e5df0158ccc99
https://usn.ubuntu.com/3754-1/
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.9
Source: MITRE
Published: 2018-05-02
Updated: 2020-07-15
Type: CWE-416
Base Score: 7.2
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 3.9
Severity: HIGH
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.8
Severity: HIGH
OR
OR
cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:6.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
131845 | EulerOS 2.0 SP2 : kernel (EulerOS-SA-2019-2353) | Nessus | Huawei Local Security Checks | critical |
130736 | EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2274) | Nessus | Huawei Local Security Checks | critical |
127408 | NewStart CGSL MAIN 4.05 : kernel Multiple Vulnerabilities (NS-SA-2019-0143) | Nessus | NewStart CGSL Local Security Checks | critical |
127192 | NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2019-0028) | Nessus | NewStart CGSL Local Security Checks | high |
127185 | NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0025) | Nessus | NewStart CGSL Local Security Checks | high |
124830 | EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1507) | Nessus | Huawei Local Security Checks | high |
124795 | EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1471) | Nessus | Huawei Local Security Checks | high |
121067 | Juniper Junos Space < 18.3R1 Multiple Vulnerabilities (JSA10917) | Nessus | Junos Local Security Checks | high |
119112 | RHEL 6 : MRG (RHSA-2018:3586) | Nessus | Red Hat Local Security Checks | high |
118947 | RHEL 7 : kernel (RHSA-2018:3590) | Nessus | Red Hat Local Security Checks | high |
118946 | RHEL 7 : kernel (RHSA-2018:3540) | Nessus | Red Hat Local Security Checks | high |
118165 | RHEL 6 : kernel (RHSA-2018:2933) | Nessus | Red Hat Local Security Checks | high |
118164 | RHEL 6 : kernel (RHSA-2018:2925) | Nessus | Red Hat Local Security Checks | high |
118163 | RHEL 6 : kernel (RHSA-2018:2924) | Nessus | Red Hat Local Security Checks | high |
117783 | RHEL 6 : kernel (RHSA-2018:2791) | Nessus | Red Hat Local Security Checks | high |
117781 | RHEL 7 : kernel (RHSA-2018:2785) | Nessus | Red Hat Local Security Checks | high |
117513 | Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2018-4214) (Foreshadow) | Nessus | Oracle Linux Local Security Checks | high |
117446 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4211) | Nessus | Oracle Linux Local Security Checks | high |
112206 | Virtuozzo 7 : OVMF / crit / criu / criu-devel / ksm-vz / etc (VZA-2018-063) | Nessus | Virtuozzo Local Security Checks | high |
112113 | Ubuntu 14.04 LTS : Linux kernel vulnerabilities (USN-3754-1) | Nessus | Ubuntu Local Security Checks | high |
111778 | Scientific Linux Security Update : kernel on SL7.x x86_64 (20180814) (Foreshadow) | Nessus | Scientific Linux Local Security Checks | high |
111736 | RHEL 7 : kernel-rt (RHSA-2018:2395) (Foreshadow) | Nessus | Red Hat Local Security Checks | high |
111727 | RHEL 7 : kernel (RHSA-2018:2384) (Foreshadow) | Nessus | Red Hat Local Security Checks | high |
111723 | Oracle Linux 7 : kernel (ELSA-2018-2384) (Foreshadow) | Nessus | Oracle Linux Local Security Checks | high |
111703 | CentOS 7 : kernel (CESA-2018:2384) (Foreshadow) | Nessus | CentOS Local Security Checks | high |
111077 | CentOS 6 : kernel (CESA-2018:2164) (Spectre) | Nessus | CentOS Local Security Checks | high |
111002 | Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20180710) (Spectre) | Nessus | Scientific Linux Local Security Checks | high |
111001 | RHEL 6 : kernel (RHSA-2018:2164) (Spectre) | Nessus | Red Hat Local Security Checks | high |
110996 | Oracle Linux 6 : kernel (ELSA-2018-2164) (Spectre) | Nessus | Oracle Linux Local Security Checks | high |
110694 | Virtuozzo 6 : parallels-server-bm-release / vzkernel / etc (VZA-2018-041) | Nessus | Virtuozzo Local Security Checks | high |
110197 | Amazon Linux AMI : kernel (ALAS-2018-1023) | Nessus | Amazon Linux Local Security Checks | high |
110136 | EulerOS 2.0 SP1 : kernel (EulerOS-SA-2018-1132) | Nessus | Huawei Local Security Checks | high |
110072 | OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0223) (Spectre) | Nessus | OracleVM Local Security Checks | high |
110071 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2018-4114) (Spectre) | Nessus | Oracle Linux Local Security Checks | high |
110041 | SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1376-1) (Spectre) | Nessus | SuSE Local Security Checks | high |
110040 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1375-1) (Spectre) | Nessus | SuSE Local Security Checks | high |
110039 | SUSE SLES12 Security Update : kernel (SUSE-SU-2018:1374-1) (Spectre) | Nessus | SuSE Local Security Checks | high |
110035 | SUSE SLES11 Security Update : kernel (SUSE-SU-2018:1368-1) (Spectre) | Nessus | SuSE Local Security Checks | high |
109177 | Amazon Linux 2 : kernel (ALAS-2018-994) | Nessus | Amazon Linux Local Security Checks | high |