First published: Tue Sep 25 2018(Updated: )
A flaw was found in the Linux kernel’s implementation of the SAS expander subsystem, where a race condition exists in the smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c. An attacker could abuse this flaw to corrupt memory and escalate privileges.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1160.rt56.1131.el7 | 0:3.10.0-1160.rt56.1131.el7 |
redhat/kernel | <0:3.10.0-1160.el7 | 0:3.10.0-1160.el7 |
redhat/kernel | <0:3.10.0-957.65.1.el7 | 0:3.10.0-957.65.1.el7 |
redhat/kernel | <0:3.10.0-1062.43.1.el7 | 0:3.10.0-1062.43.1.el7 |
Linux Linux kernel | <3.16.72 | |
Linux Linux kernel | >=3.17<3.18.140 | |
Linux Linux kernel | >=3.19<4.4.180 | |
Linux Linux kernel | >=4.5<4.9.175 | |
Linux Linux kernel | >=4.10<4.14.118 | |
Linux Linux kernel | >=4.15<4.19.42 | |
Canonical Ubuntu Linux | =16.04 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
F5 Traffix Signaling Delivery Controller | =5.0.0 | |
F5 Traffix Signaling Delivery Controller | =5.1.0 | |
Netapp Active Iq Unified Manager Vmware Vsphere | >=9.5 | |
Netapp Snapprotect | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp Solidfire \& Hci Storage Node | ||
Netapp Storage Replication Adapter For Clustered Data Ontap Vmware Vsphere | ||
Netapp Vasa Provider For Clustered Data Ontap | >=7.2 | |
Netapp Virtual Storage Console Vmware Vsphere | >=7.2 | |
Netapp Hci Compute Node | ||
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)