CVE-2017-10911
published 2017-07-05CVE-2017-10911: The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from…
PriorityP427medium6.5CVSS 3.0
AVLACLPRLUINSCCHINAN
EPSS
0.45%
36.4th percentile
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.11.11-1 (bookworm) | linux 4.11.11-1 (bookworm) |
| debian | qemu | < linux 4.11.11-1 (bookworm) | linux 4.11.11-1 (bookworm) |
| linux | linux_kernel | <= 4.11.7 | — |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 4.11.11-1 | 4.11.11-1 |
| linux | linux_kernel | >= 0 < 3.13.0-135.184 | 3.13.0-135.184 |
| linux | linux_kernel | >= 0 < 4.4.0-98.121 | 4.4.0-98.121 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 1:2.8+dfsg-7 | 1:2.8+dfsg-7 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.36 | 2.0.0+dfsg-2ubuntu1.36 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.35 | 2.0.0+dfsg-2ubuntu1.35 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.16 | 1:2.5+dfsg-5ubuntu10.16 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.15 | 1:2.5+dfsg-5ubuntu10.15 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ch8x-4fwh-q3hq: The make_response function in drivers/block/xen-blkback/blkback
ghsa_unreviewed·2022-05-14
CVE-2017-10911 [MEDIUM] CWE-200 GHSA-ch8x-4fwh-q3hq: The make_response function in drivers/block/xen-blkback/blkback
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
OSV
linux-lts-xenial vulnerabilities
osv·2017-10-31·CVSS 6.5
[MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3469-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2017-10911)
Bo Zhang discovered that the netlink wireless configuration interface in
the Linux kernel did not properly validate attributes when handling certain
requests. A local attacker with the CAP_NET_ADMIN could use this to cause a
denial of service (system crash). (CVE-2017-12153)
OSV
linux vulnerabilities
osv·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] linux vulnerabilities
linux vulnerabilities
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10661)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary co
OSV
linux-gcp vulnerabilities
osv·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] linux-gcp vulnerabilities
linux-gcp vulnerabilities
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2017-10911)
It was disc
OSV
linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2017-10-31·CVSS 6.5
CVE-2017-10911 [MEDIUM] linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-gke, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2017-10911)
Bo Zhang discovered that the netlink wireless configuration interface in
the Linux kernel did not properly validate attributes when handling certain
requests. A local attacker with the CAP_NET_ADMIN could use this to cause a
denial of service (system crash). (CVE-2017-12153)
It was discovered that the nested KVM implementation in the Linux
kernel in some situations did not properly prevent second level guests
from reading and writ
OSV
linux-hwe vulnerabilities
osv·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3468-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initi
OSV
qemu regression
osv·2017-09-20·CVSS 7.8
CVE-2017-9375 [HIGH] qemu regression
qemu regression
USN-3414-1 fixed vulnerabilities in QEMU. The patch backport for
CVE-2017-9375 was incomplete and caused a regression in the USB xHCI
controller emulation support. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Leo Gaspard discovered that QEMU incorrectly handled VirtFS access control.
A guest attacker could use this issue to elevate privileges inside the
guest. (CVE-2017-7493)
Li Qiang discovered that QEMU incorrectly handled VMWare PVSCSI emulation.
A privileged attacker inside the guest could use this issue to cause QEMU
to consume resources or crash, resulting in a denial of service.
(CVE-2017-8112)
It was discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2 Host
Bus Adapter emulation support. A privileged at
OSV
qemu vulnerabilities
osv·2017-09-13·CVSS 7.8
CVE-2017-7493 [HIGH] qemu vulnerabilities
qemu vulnerabilities
Leo Gaspard discovered that QEMU incorrectly handled VirtFS access control.
A guest attacker could use this issue to elevate privileges inside the
guest. (CVE-2017-7493)
Li Qiang discovered that QEMU incorrectly handled VMWare PVSCSI emulation.
A privileged attacker inside the guest could use this issue to cause QEMU
to consume resources or crash, resulting in a denial of service.
(CVE-2017-8112)
It was discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2 Host
Bus Adapter emulation support. A privileged attacker inside the guest could
use this issue to cause QEMU to crash, resulting in a denial of service, or
possibly to obtain sensitive host memory. This issue only affected Ubuntu
16.04 LTS and Ubuntu 17.04. (CVE-2017-8380)
Li Qiang discovered that QEMU i
OSV
CVE-2017-10911: The make_response function in drivers/block/xen-blkback/blkback
osv·2017-07-05·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911: The make_response function in drivers/block/xen-blkback/blkback
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 6.5
CVE-2017-10911 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2017-10911)
Bo Zhang discovered that the netlink wireless configuration interface in
the Linux kernel did not properly validate attributes when handling certain
requests. A local attacker with the CAP_NET_ADMIN could use this to cause a
denial of service (system crash). (CVE-2017-12153)
It was discovered that the nested KVM implementation in the Linux
kernel in some situations did not properly prevent second level guests
from r
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3468-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
in
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 5.5
CVE-2017-1000252 [MEDIUM] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM subsystem in the Linux kernel did not
properly bound guest IRQs. A local attacker in a guest VM could use this to
cause a denial of service (host system crash). (CVE-2017-1000252)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10663)
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2017-10661)
It was discovered that the Flash-Friendly File System (f2fs) implementation
in the Linux kernel did not properly validate superblock metadata. A local
attacker could use t
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 7.8
CVE-2016-8632 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3470-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Qian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()
function in the Linux kernel. A local attacker could use to cause a denial
of service (system crash) or possibly execute arbitrary code with
administrative privileges. (CVE-2016-8632)
Dmitry Vyukov discovered that a race condition existed in the timerfd
subsystem of the Linux kernel when handling might_cancel queuing. A local
attacker could use this to cause a denial of service (system crash
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2017-10-31·CVSS 6.5
CVE-2017-10911 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3469-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Anthony Perard discovered that the Xen virtual block driver did not
properly initialize some data structures before passing them to user space.
A local attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2017-10911)
Bo Zhang discovered that the netlink wireless configuration interface in
the Linux kernel did not properly validate attributes when handling certain
requests. A local attacker with the CAP_NET_
Ubuntu
QEMU regression
vendor_ubuntu·2017-09-20·CVSS 7.8
CVE-2017-9375 [HIGH] QEMU regression
Title: QEMU regression
Summary: USN-3414-1 introduced a regression in QEMU.
USN-3414-1 fixed vulnerabilities in QEMU. The patch backport for
CVE-2017-9375 was incomplete and caused a regression in the USB xHCI
controller emulation support. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Leo Gaspard discovered that QEMU incorrectly handled VirtFS access control.
A guest attacker could use this issue to elevate privileges inside the
guest. (CVE-2017-7493)
Li Qiang discovered that QEMU incorrectly handled VMWare PVSCSI emulation.
A privileged attacker inside the guest could use this issue to cause QEMU
to consume resources or crash, resulting in a denial of service.
(CVE-2017-8112)
It was discovered that QEMU incorrectly handled MegaRAID SA
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2017-09-13·CVSS 7.8
CVE-2017-10664 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Leo Gaspard discovered that QEMU incorrectly handled VirtFS access control.
A guest attacker could use this issue to elevate privileges inside the
guest. (CVE-2017-7493)
Li Qiang discovered that QEMU incorrectly handled VMWare PVSCSI emulation.
A privileged attacker inside the guest could use this issue to cause QEMU
to consume resources or crash, resulting in a denial of service.
(CVE-2017-8112)
It was discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2 Host
Bus Adapter emulation support. A privileged attacker inside the guest could
use this issue to cause QEMU to crash, resulting in a denial of service, or
possibly to obtain sensitive host memory. This issue only affected Ubuntu
16.04 LTS and U
Red Hat
xen: blkif responses leak backend stack data (XSA-216)
vendor_redhat·2017-06-20·CVSS 6.5
CVE-2017-10911 [MEDIUM] CWE-203 xen: blkif responses leak backend stack data (XSA-216)
xen: blkif responses leak backend stack data (XSA-216)
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux
Debian
CVE-2017-10911: linux - The make_response function in drivers/block/xen-blkback/blkback.c in the Linux k...
vendor_debian·2017·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911: linux - The make_response function in drivers/block/xen-blkback/blkback.c in the Linux k...
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Scope: local
bookworm: resolved (fixed in 4.11.11-1)
bullseye: resolved (fixed in 4.11.11-1)
forky: resolved (fixed in 4.11.11-1)
sid: resolved (fixed in 4.11.11-1)
trixie: resolved (fixed in 4.11.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
bugzilla·2017-06-20·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also men
Bugzilla
CVE-2017-10911 xsa216 xen: blkif responses leak backend stack data (XSA-216)
bugzilla·2017-06-05·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911 xsa216 xen: blkif responses leak backend stack data (XSA-216)
CVE-2017-10911 xsa216 xen: blkif responses leak backend stack data (XSA-216)
ISSUE DESCRIPTION
The block interface response structure has some discontiguous fields.
Certain backends populate the structure fields of an otherwise
uninitialized instance of this structure on their stacks, leaking
data through the (internal or trailing) padding field.
IMPACT
A malicious unprivileged guest may be able to obtain sensitive
information from the host or other guests.
VULNERABLE SYSTEMS
All Linux versions supporting the xen-blkback, blkback, or blktap
drivers are vulnerable.
FreeBSD, NetBSD and Windows (with our without PV drivers) are not
vulnerable (either because they do not have backends at all, or
because they use a different implementation technique which does not
suffer from this proble
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341http://www.debian.org/security/2017/dsa-3920http://www.debian.org/security/2017/dsa-3927http://www.debian.org/security/2017/dsa-3945http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8http://www.securityfocus.com/bid/99162http://www.securitytracker.com/id/1038720https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-216.htmlhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341http://www.debian.org/security/2017/dsa-3920http://www.debian.org/security/2017/dsa-3927http://www.debian.org/security/2017/dsa-3945http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8http://www.securityfocus.com/bid/99162http://www.securitytracker.com/id/1038720https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlhttps://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-216.html
2017-07-05
Published