MGASA-2017-0278

Advisory lineage Upstream: 2 Downstream: 0
Published: 18 Aug 2017, 17:06
Last modified:16 Apr 2026, 06:25

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Aug 2017, 17:06
Published
Vulnerability first disclosed
16 Apr 2026, 06:25
Last Modified
Vulnerability information updated

Description

Updated kernel packages fixes security and other bugs This kernel update is based on upstream 4.9.43 and fixes at least the following security issues: The curseg->segno call in f2fs driver can be malformed so that it will have a value that triggers an out of boundary write that could cause memory corruption on the affected devices, leading to code execution in the kernel context. This would allow for more data to be accessed and controlled by the malware (CVE-2017-10663). The UDP Fragmentation Offload (UFO) feature is vulnerable to out-of-bounds writes causing exploitable memory corruption. If unprivileged user namespaces are available, this bug can be exploited to gain root privileges (CVE-2017-1000112). For other upstream fixes in this update, read the referenced changelogs.

Affected Systems

  • mageiakernel

    < 4.9.43-1.mga6

  • mageiakernel-userspace-headers

    < 4.9.43-1.mga6

  • mageiakmod-vboxadditions

    < 5.1.26-2.mga6

  • mageiakmod-virtualbox

    < 5.1.26-2.mga6

  • mageiakmod-xtables-addons

    < 2.12-41.mga6

References (5)