vulnerability

Ubuntu: (Multiple Advisories) (CVE-2017-0627): Linux kernel vulnerabilities

Severity
3
CVSS
(AV:N/AC:H/Au:N/C:P/I:N/A:N)
Published
May 12, 2017
Added
Jun 13, 2018
Modified
Aug 18, 2025

Description

It was discovered that the netfilter subsystem of the Linux kernel did not
properly validate ebtables offsets. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2018-1068)

It was discovered that a NULL pointer dereference existed in the RDS
(Reliable Datagram Sockets) protocol implementation in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2018-7492)

Eyal Itkin discovered that the USB displaylink video adapter driver in the
Linux kernel did not properly validate mmap offsets sent from userspace. A
local attacker could use this to expose sensitive information (kernel
memory) or possibly execute arbitrary code. (CVE-2018-8781)

Xingyuan Lin discovered that a out-of-bounds read existed in the USB Video
Class (UVC) driver of the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2017-0627)

Solutions

ubuntu-upgrade-linux-image-3-13-0-151-genericubuntu-upgrade-linux-image-3-13-0-151-generic-lpaeubuntu-upgrade-linux-image-3-13-0-151-lowlatencyubuntu-upgrade-linux-image-3-13-0-151-powerpc-e500ubuntu-upgrade-linux-image-3-13-0-151-powerpc-e500mcubuntu-upgrade-linux-image-3-13-0-151-powerpc-smpubuntu-upgrade-linux-image-3-13-0-151-powerpc64-embubuntu-upgrade-linux-image-3-13-0-151-powerpc64-smpubuntu-upgrade-linux-image-genericubuntu-upgrade-linux-image-generic-lpaeubuntu-upgrade-linux-image-generic-lpae-lts-trustyubuntu-upgrade-linux-image-generic-lts-trustyubuntu-upgrade-linux-image-lowlatencyubuntu-upgrade-linux-image-powerpc-e500ubuntu-upgrade-linux-image-powerpc-e500mcubuntu-upgrade-linux-image-powerpc-smpubuntu-upgrade-linux-image-powerpc64-embubuntu-upgrade-linux-image-powerpc64-smp

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.