Amazon Linux AMI : kernel (ALAS-2019-1279)

Low Nessus Plugin ID 129006

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use the obtained kernel pointer to discover the location of kernel code and data and bypass kernel security protections such as KASLR.(CVE-2018-7755)

Note: The Release Date is incorrect. This CVE was fixed Nov 2018

Solution

Run 'yum update kernel' and reboot the instance to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2019-1279.html

Plugin Details

Severity: Low

ID: 129006

File Name: ala_ALAS-2019-1279.nasl

Version: 1.1

Type: local

Agent: unix

Published: 2019/09/19

Updated: 2019/09/19

Dependencies: 12634

Risk Information

Risk Factor: Low

CVSS v2.0

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS v3.0

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-debuginfo-common-i686, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:perf-debuginfo, cpe:/o:amazon:linux

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 2019/09/18

Vulnerability Publication Date: 2018/03/08

Reference Information

CVE: CVE-2018-7755

ALAS: 2019-1279