APPLIED: [CVE A/B] CVE-2018-11508 -- compat_get_timex information leak

Khaled Elmously khalid.elmously at canonical.com
Fri Jun 8 21:49:07 UTC 2018


Marking subject as applied

On 2018-06-08 15:29:06 , Andy Whitcroft wrote:
> CVE-2018-11508:
> 	The compat_get_timex function in kernel/compat.c in the
> 	Linux kernel before 4.16.9 allows local users to obtain
> 	sensitive information from kernel memory via adjtimex.
> 
> Following this email is a patch for bionic/linux and artful/linux.  This
> is a clean cherry-pick in both series.  Earlier series are unaffected by
> this issue.
> 
> Proposing for SRU to artful and bionic.
> 
> -apw
> 
> -- 
> kernel-team mailing list
> kernel-team at lists.ubuntu.com
> https://lists.ubuntu.com/mailman/listinfo/kernel-team




More information about the kernel-team mailing list