First published: Tue Sep 25 2018(Updated: )
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1160.rt56.1131.el7 | 0:3.10.0-1160.rt56.1131.el7 |
redhat/kernel | <0:3.10.0-1160.el7 | 0:3.10.0-1160.el7 |
redhat/kernel | <0:3.10.0-957.65.1.el7 | 0:3.10.0-957.65.1.el7 |
redhat/kernel | <0:3.10.0-1062.43.1.el7 | 0:3.10.0-1062.43.1.el7 |
ubuntu/linux | <4.15.0-44.47 | 4.15.0-44.47 |
ubuntu/linux | <4.18.0-14.15 | 4.18.0-14.15 |
ubuntu/linux | <4.20~ | 4.20~ |
ubuntu/linux | <4.4.0-157.185 | 4.4.0-157.185 |
ubuntu/linux-aws | <4.15.0-1032.34 | 4.15.0-1032.34 |
ubuntu/linux-aws | <4.18.0-1008.10 | 4.18.0-1008.10 |
ubuntu/linux-aws | <4.20~ | 4.20~ |
ubuntu/linux-aws | <4.4.0-1090.101 | 4.4.0-1090.101 |
ubuntu/linux-aws-hwe | <4.20~ | 4.20~ |
ubuntu/linux-aws-hwe | <4.15.0-1032.34~16.04.1 | 4.15.0-1032.34~16.04.1 |
ubuntu/linux-azure | <4.15.0-1037.39 | 4.15.0-1037.39 |
ubuntu/linux-azure | <4.18.0-1008.8 | 4.18.0-1008.8 |
ubuntu/linux-azure | <4.20~ | 4.20~ |
ubuntu/linux-azure | <4.15.0-1037.39~16.04.1 | 4.15.0-1037.39~16.04.1 |
ubuntu/linux-azure-edge | <4.15.0-1037.39 | 4.15.0-1037.39 |
ubuntu/linux-azure-edge | <4.20~ | 4.20~ |
ubuntu/linux-azure-edge | <4.15.0-1037.39~16.04.1 | 4.15.0-1037.39~16.04.1 |
ubuntu/linux-euclid | <4.20~ | 4.20~ |
ubuntu/linux-flo | <4.20~ | 4.20~ |
ubuntu/linux-gcp | <4.15.0-1027.28 | 4.15.0-1027.28 |
ubuntu/linux-gcp | <4.18.0-1006.7 | 4.18.0-1006.7 |
ubuntu/linux-gcp | <4.20~ | 4.20~ |
ubuntu/linux-gcp | <4.15.0-1027.28~16.04.1 | 4.15.0-1027.28~16.04.1 |
ubuntu/linux-gcp-edge | <4.18.0-1006.7~18.04.1 | 4.18.0-1006.7~18.04.1 |
ubuntu/linux-gcp-edge | <4.20~ | 4.20~ |
ubuntu/linux-gke | <4.20~ | 4.20~ |
ubuntu/linux-gke-4.15 | <4.20~ | 4.20~ |
ubuntu/linux-gke-5.0 | <4.20~ | 4.20~ |
ubuntu/linux-goldfish | <4.20~ | 4.20~ |
ubuntu/linux-grouper | <4.20~ | 4.20~ |
ubuntu/linux-hwe | <4.18.0-14.15~18.04.1 | 4.18.0-14.15~18.04.1 |
ubuntu/linux-hwe | <4.20~ | 4.20~ |
ubuntu/linux-hwe | <4.15.0-45.48~16.04.1 | 4.15.0-45.48~16.04.1 |
ubuntu/linux-hwe-edge | <4.20~ | 4.20~ |
ubuntu/linux-hwe-edge | <4.15.0-45.48~16.04.1 | 4.15.0-45.48~16.04.1 |
ubuntu/linux-kvm | <4.15.0-1029.29 | 4.15.0-1029.29 |
ubuntu/linux-kvm | <4.18.0-1007.7 | 4.18.0-1007.7 |
ubuntu/linux-kvm | <4.20~ | 4.20~ |
ubuntu/linux-kvm | <4.4.0-1052.59 | 4.4.0-1052.59 |
ubuntu/linux-lts-trusty | <4.20~ | 4.20~ |
ubuntu/linux-lts-utopic | <4.20~ | 4.20~ |
ubuntu/linux-lts-vivid | <4.20~ | 4.20~ |
ubuntu/linux-lts-wily | <4.20~ | 4.20~ |
ubuntu/linux-lts-xenial | <4.20~ | 4.20~ |
ubuntu/linux-maguro | <4.20~ | 4.20~ |
ubuntu/linux-mako | <4.20~ | 4.20~ |
ubuntu/linux-manta | <4.20~ | 4.20~ |
ubuntu/linux-oem | <4.15.0-1033.38 | 4.15.0-1033.38 |
ubuntu/linux-oem | <4.15.0-1033.38 | 4.15.0-1033.38 |
ubuntu/linux-oem | <4.20~ | 4.20~ |
ubuntu/linux-oracle | <4.15.0-1008.10 | 4.15.0-1008.10 |
ubuntu/linux-oracle | <4.15.0-1008.10 | 4.15.0-1008.10 |
ubuntu/linux-oracle | <4.20~ | 4.20~ |
ubuntu/linux-oracle | <4.15.0-1008.10~16.04.1 | 4.15.0-1008.10~16.04.1 |
ubuntu/linux-raspi2 | <4.15.0-1031.33 | 4.15.0-1031.33 |
ubuntu/linux-raspi2 | <4.18.0-1009.11 | 4.18.0-1009.11 |
ubuntu/linux-raspi2 | <4.20~ | 4.20~ |
ubuntu/linux-raspi2 | <4.4.0-1117.126 | 4.4.0-1117.126 |
ubuntu/linux-snapdragon | <4.15.0-1053.57 | 4.15.0-1053.57 |
ubuntu/linux-snapdragon | <4.20~ | 4.20~ |
ubuntu/linux-snapdragon | <4.4.0-1121.127 | 4.4.0-1121.127 |
Linux Linux kernel | <3.16.72 | |
Linux Linux kernel | >=3.17<3.18.140 | |
Linux Linux kernel | >=3.19<4.4.180 | |
Linux Linux kernel | >=4.5<4.9.175 | |
Linux Linux kernel | >=4.10<4.14.118 | |
Linux Linux kernel | >=4.15<4.19.42 | |
Canonical Ubuntu Linux | =16.04 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
F5 Traffix Signaling Delivery Controller | =5.0.0 | |
F5 Traffix Signaling Delivery Controller | =5.1.0 | |
Netapp Active Iq Unified Manager Vmware Vsphere | >=9.5 | |
Netapp Snapprotect | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp Solidfire \& Hci Storage Node | ||
Netapp Storage Replication Adapter For Clustered Data Ontap Vmware Vsphere | ||
Netapp Vasa Provider For Clustered Data Ontap | >=7.2 | |
Netapp Virtual Storage Console Vmware Vsphere | >=7.2 | |
Netapp Hci Compute Node | ||
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
debian/linux | 5.10.218-1 6.1.94-1 6.1.90-1 6.8.12-1 6.9.7-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)