CVE-2018-16276
published 2018-08-31CVE-2018-16276: An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.44%
36.2th percentile
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.17.8-1 (bookworm) | linux 4.17.8-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.17.8-1 | 4.17.8-1 |
| linux | linux_kernel | >= 0 < 4.17.8-1 | 4.17.8-1 |
| linux | linux_kernel | >= 0 < 4.17.8-1 | 4.17.8-1 |
| linux | linux_kernel | >= 0 < 4.17.8-1 | 4.17.8-1 |
| linux | linux_kernel | >= 0 < 3.13.0-164.214 | 3.13.0-164.214 |
| linux | linux_kernel | >= 0 < 4.4.0-137.163 | 4.4.0-137.163 |
| linux | linux_kernel | >= 0 < 4.15.0-43.46 | 4.15.0-43.46 |
| linux | linux_kernel | >= 2.6.37 < 3.16.58 | 3.16.58 |
| linux | linux_kernel | >= 3.17 < 3.18.116 | 3.18.116 |
| linux | linux_kernel | >= 3.19 < 4.4.141 | 4.4.141 |
| linux | linux_kernel | >= 4.10 < 4.14.56 | 4.14.56 |
| linux | linux_kernel | >= 4.15 < 4.17.7 | 4.17.7 |
| linux | linux_kernel | >= 4.5 < 4.9.113 | 4.9.113 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wjj9-4g79-4c2c: An issue was discovered in yurex_read in drivers/usb/misc/yurex
ghsa_unreviewed·2022-05-14
CVE-2018-16276 [HIGH] CWE-20 GHSA-wjj9-4g79-4c2c: An issue was discovered in yurex_read in drivers/usb/misc/yurex
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
OSV
linux vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux ke
OSV
linux-azure vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] linux-azure vulnerabilities
linux-azure vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-12-20·CVSS 7.8
[HIGH] linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerabili
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that the YURE
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-10-01·CVSS 5.5
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3776-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-10-01·CVSS 5.5
CVE-2018-17182 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads v
OSV
CVE-2018-16276: An issue was discovered in yurex_read in drivers/usb/misc/yurex
osv·2018-08-31·CVSS 7.8
CVE-2018-16276 [HIGH] CVE-2018-16276: An issue was discovered in yurex_read in drivers/usb/misc/yurex
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus d
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the Linux kernel. An attacker could use this
to cause a denial of service (system crash). (CVE-2018-14734)
It was discovered that
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-a
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2017-2647 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3849-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that a NULL pointer dereference existed in the keyring
subsystem of the Linux kernel. A local attacker could use this to cause a
denial of service (system crash). (CVE-2017-2647)
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was di
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2018-12-20·CVSS 7.8
CVE-2018-10902 [HIGH] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered th
Red Hat
kernel: Out-of-bounds read in drivers/usb/misc/yurex.c:yurex_read allows for DoS or potential code execution
vendor_redhat·2018-11-19·CVSS 7.8
CVE-2018-19270 [HIGH] CWE-125 kernel: Out-of-bounds read in drivers/usb/misc/yurex.c:yurex_read allows for DoS or potential code execution
kernel: Out-of-bounds read in drivers/usb/misc/yurex.c:yurex_read allows for DoS or potential code execution
No description is available for this CVE.
Statement: This flaw was found to be a duplicate of CVE-2018-16276. Please see https://access.redhat.com/security/cve/CVE-2018-16276 for information about affected products and security errata.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 5.5
CVE-2017-18216 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
u
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 5.5
CVE-2017-18216 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3776-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Jann Horn discovered that the vmacache subsystem did not properly handle
sequence number overflows, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or execute arbitrary code. (CVE-2018-17182)
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A l
Red Hat
kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c
vendor_redhat·2018-07-06·CVSS 7.8
CVE-2018-16276 [HIGH] CWE-119 kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c
kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
An out-of-bounds access issue was discovered in yurex_read() in drivers/usb/misc/yurex.c in the Linux kernel. A local attacker could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Pack
Debian
CVE-2018-16276: linux - An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux k...
vendor_debian·2018·CVSS 7.8
CVE-2018-16276 [HIGH] CVE-2018-16276: linux - An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux k...
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
Scope: local
bookworm: resolved (fixed in 4.17.8-1)
bullseye: resolved (fixed in 4.17.8-1)
forky: resolved (fixed in 4.17.8-1)
sid: resolved (fixed in 4.17.8-1)
trixie: resolved (fixed in 4.17.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19270 kernel: Out-of-bounds read in drivers/usb/misc/yurex.c:yurex_read allows for DoS or potential code execution
bugzilla·2018-11-19·CVSS 7.8
CVE-2018-19270 [HIGH] CVE-2018-19270 kernel: Out-of-bounds read in drivers/usb/misc/yurex.c:yurex_read allows for DoS or potential code execution
CVE-2018-19270 kernel: Out-of-bounds read in drivers/usb/misc/yurex.c:yurex_read allows for DoS or potential code execution
In yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7, an out-of-bounds user space access in the read handler of the yurex USB device driver could be used by local attackers to crash the kernel or potentially escalate privileges.
Reference:
https://bugzilla.suse.com/show_bug.cgi?id=1115593
Upstream Patch:
https://github.com/torvalds/linux/commit/f1e255d6
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f1e255d6
Discussion:
*** This bug has been marked as a duplicate of bug 1624507 ***
---
Statement:
This flaw was found to be a duplicate of CVE-2018-16276. Please see https://access.redhat.com/security/cve/CVE-2
Bugzilla
CVE-2018-16276 kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c
bugzilla·2018-08-31·CVSS 7.8
CVE-2018-16276 [HIGH] CVE-2018-16276 kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c
CVE-2018-16276 kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c
An out-of-bound access issue was discovered in yurex_read() in drivers/usb/misc/yurex.c in the Linux kernel. A local attacker could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
References:
https://marc.info/?t=153089016500001&r=1&w=2
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.7
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f1e255d60ae66a9f672ff9a207ee6cd8e33d2679
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1624508]
---
This was fixed for Fedora with the 4.17.7 stable updates.
---
Note:
No R
Bugzilla
CVE-2018-16276 kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c [fedora-all]
bugzilla·2018-08-31·CVSS 7.8
CVE-2018-16276 [HIGH] CVE-2018-16276 kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c [fedora-all]
CVE-2018-16276 kernel: incorrect bounds checking in yurex_read in drivers/usb/misc/yurex.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f1e255d60ae66a9f672ff9a207ee6cd8e33d2679https://bugzilla.suse.com/show_bug.cgi?id=1106095https://bugzilla.suse.com/show_bug.cgi?id=1115593https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.7https://github.com/torvalds/linux/commit/f1e255d60ae66a9f672ff9a207ee6cd8e33d2679https://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://usn.ubuntu.com/3776-1/https://usn.ubuntu.com/3776-2/https://usn.ubuntu.com/3847-1/https://usn.ubuntu.com/3847-2/https://usn.ubuntu.com/3847-3/https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/https://www.debian.org/security/2018/dsa-4308http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f1e255d60ae66a9f672ff9a207ee6cd8e33d2679https://bugzilla.suse.com/show_bug.cgi?id=1106095https://bugzilla.suse.com/show_bug.cgi?id=1115593https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.7https://github.com/torvalds/linux/commit/f1e255d60ae66a9f672ff9a207ee6cd8e33d2679https://lists.debian.org/debian-lts-announce/2018/10/msg00003.htmlhttps://usn.ubuntu.com/3776-1/https://usn.ubuntu.com/3776-2/https://usn.ubuntu.com/3847-1/https://usn.ubuntu.com/3847-2/https://usn.ubuntu.com/3847-3/https://usn.ubuntu.com/3849-1/https://usn.ubuntu.com/3849-2/https://www.debian.org/security/2018/dsa-4308
2018-08-31
Published