Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.1550 [DLA 1771-1] linux-4.9 security update 6 May 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: linux-4.9 Publisher: Debian Operating System: Debian GNU/Linux Debian GNU/Linux 8 Impact/Access: Root Compromise -- Existing Account Access Privileged Data -- Remote/Unauthenticated Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2019-9213 CVE-2019-8980 CVE-2019-7222 CVE-2019-7221 CVE-2019-6974 CVE-2019-3819 CVE-2019-3701 CVE-2019-3460 CVE-2019-3459 CVE-2018-1000026 CVE-2018-20169 CVE-2018-19985 CVE-2018-19824 CVE-2018-16884 CVE-2018-14625 Reference: ESB-2019.1390 ESB-2019.1389 ESB-2019.1189 ESB-2019.1127 ESB-2019.1126 Original Bulletin: https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html - --------------------------BEGIN INCLUDED TEXT-------------------- Package : linux-4.9 Version : 4.9.168-1~deb8u1 CVE ID : CVE-2018-14625 CVE-2018-16884 CVE-2018-19824 CVE-2018-19985 CVE-2018-20169 CVE-2018-1000026 CVE-2019-3459 CVE-2019-3460 CVE-2019-3701 CVE-2019-3819 CVE-2019-6974 CVE-2019-7221 CVE-2019-7222 CVE-2019-8980 CVE-2019-9213 Debian Bug : 904385 918103 922306 Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2018-14625 A use-after-free bug was found in the vhost driver for the Virtual Socket protocol. If this driver is used to communicate with a malicious virtual machine guest, the guest could read sensitive information from the host kernel. CVE-2018-16884 A flaw was found in the NFS 4.1 client implementation. Mounting NFS shares in multiple network namespaces at the same time could lead to a user-after-free. Local users might be able to use this for denial of service (memory corruption or crash) or possibly for privilege escalation. This can be mitigated by disabling unprivileged users from creating user namespaces, which is the default in Debian. CVE-2018-19824 Hui Peng and Mathias Payer discovered a use-after-free bug in the USB audio driver. A physically present attacker able to attach a specially designed USB device could use this for privilege escalation. CVE-2018-19985 Hui Peng and Mathias Payer discovered a missing bounds check in the hso USB serial driver. A physically present user able to attach a specially designed USB device could use this to read sensitive information from the kernel or to cause a denial of service (crash). CVE-2018-20169 Hui Peng and Mathias Payer discovered missing bounds checks in the USB core. A physically present attacker able to attach a specially designed USB device could use this to cause a denial of service (crash) or possibly for privilege escalation. CVE-2018-1000026 It was discovered that Linux could forward aggregated network packets with a segmentation size too large for the output device. In the specific case of Broadcom NetXtremeII 10Gb adapters, this would result in a denial of service (firmware crash). This update adds a mitigation to the bnx2x driver for this hardware. CVE-2019-3459, CVE-2019-3460 Shlomi Oberman, Yuli Shapiro and Karamba Security Ltd. research team discovered missing range checks in the Bluetooth L2CAP implementation. If Bluetooth is enabled, a nearby attacker could use these to read sensitive information from the kernel. CVE-2019-3701 Muyu Yu and Marcus Meissner reported that the CAN gateway implementation allowed the frame length to be modified, typically resulting in out-of-bounds memory-mapped I/O writes. On a system with CAN devices present, a local user with CAP_NET_ADMIN capability in the initial net namespace could use this to cause a crash (oops) or other hardware-dependent impact. CVE-2019-3819 A potential infinite loop was discovered in the HID debugfs interface exposed under /sys/kernel/debug/hid. A user with access to these files could use this for denial of service. This interface is only accessible to root by default, which fully mitigates the issue. CVE-2019-6974 Jann Horn reported a use-after-free bug in KVM. A local user with access to /dev/kvm could use this to cause a denial of service (memory corruption or crash) or possibly for privilege escalation. CVE-2019-7221 Jim Mattson and Felix Wilhelm reported a user-after-free bug in KVM's nested VMX implementation. On systems with Intel CPUs, a local user with access to /dev/kvm could use this to cause a denial of service (memory corruption or crash) or possibly for privilege escalation. Nested VMX is disabled by default, which fully mitigates the issue. CVE-2019-7222 Felix Wilhelm reported an information leak in KVM for x86. A local user with access to /dev/kvm could use this to read sensitive information from the kernel. CVE-2019-8980 A bug was discovered in the kernel_read_file() function used to load firmware files. In certain error conditions it could leak memory, which might lead to a denial of service. This is probbaly not exploitable in a Debian system. CVE-2019-9213 Jann Horn reported that privileged tasks could cause stack segments, including those in other processes, to grow downward to address 0. On systems lacking SMAP (x86) or PAN (ARM), this exacerbated other vulnerabilities: a null pointer dereference could be exploited for privilege escalation rather than only for denial of service. For Debian 8 "Jessie", these problems have been fixed in version 4.9.168-1~deb8u1. This version also includes fixes for Debian bugs #904385, #918103, and #922306; and other fixes included in upstream stable updates. We recommend that you upgrade your linux-4.9 and linux-latest-4.9 packages. You will need to use "apt-get upgrade --with-new-pkgs" or "apt upgrade" as the binary package names have changed. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -- Ben Hutchings - Debian developer, member of kernel, installer and LTS teams - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXM+DnmaOgq3Tt24GAQgYpRAAkb5BQsKdJdgqVApxhtIBxW5cyEO7Oy3C BalGUd0hTP9919/L/Bez7eXqF/C/zLxqAJOzfj/UuG+1yWgo4UlmtFmJ7vC8PzIL RczNWuIULfcdso3fKdo4oAFzULwSdO27iMNZ3T9jqvmR+gM9ZPk2c45lxu3HDT/C CkVBtQ/kMcqE5R7accKHUYaEgNtSJuaeVnIVFkh7oXqzWHoKZQBTcEmBnLcEl3hH bVGuV7nkzizTnJx97l1p06B8kI4LrZOLEkGSikUS9VmI7pQt0rfirp1UxHlvHIJ+ aT9wF0uYewV5QjHnfVN9LIndFldFWQVtoZBYcvAz92G3WZARf8reSdyKTQWGEW3Z BWcophMlRjyrbW902nBkM/O15vGyM2YOPRKA26ztkSEu54Z97VysoIm+WL5KelqT L363mSWRsFrAhVDouc9MA1eW1H6l5RUFpCY1F7bLvjWRxP5cDD3Tz5Az2PELw8a6 QKpzuT1doerApyunNW6WUM45DOz5khRM46vDNBEpVvtYF//Cuw8QQEuQB7mJRM6d TnotK/kuUctNoNBzDwKkCr+iDjohSv+VUFLHQ2q9M23+HFn4U8KUyyevgPFy7fR6 ZArGUfrx8+8hOf+4P4d3fKLZ6YQ4chwk7ZUOznCfOMd1I9Ryr2EqXbYAH9tv4Vfg DLqVJHklFdk= =LY2R -----END PGP SIGNATURE-----