USN-3358-1: Linux kernel vulnerabilities
It was discovered that the Linux kernel did not properly initialize a Wake- on-Lan data structure. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2014-9900) Alexander Potapenko discovered a race condition in the Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2017-1000380) Li Qiang discovered that the DRM driver for VMware Virtual GPUs in the Linux kernel did not properly validate some ioctl arguments. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-7346) Murray McAllister discovered that the DRM driver for VMware Virtual GPUs in the Linux kernel did not properly initialize memory. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2017-9605)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2014-9900?
The severity of CVE-2014-9900 is moderate.
How can a local attacker exploit CVE-2014-9900?
A local attacker can exploit CVE-2014-9900 to expose sensitive information in kernel memory.
Which versions of Ubuntu are affected by CVE-2014-9900?
Ubuntu 17.04 is affected by CVE-2014-9900.
What is the remedy for CVE-2014-9900?
The remedy for CVE-2014-9900 is to update to Linux kernel version 4.10.0-28.32 or later.
Where can I find more information about CVE-2014-9900?
You can find more information about CVE-2014-9900 on the Ubuntu website.