USN-3364-1

Advisory lineage Upstream: 12 Downstream: 0
Published: 24 Jul 2017, 22:30
Last modified:22 Apr 2026, 09:37

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Jul 2017, 22:30
Published
Vulnerability first disclosed
22 Apr 2026, 09:37
Last Modified
Vulnerability information updated

Description

linux, linux-raspi2, linux-snapdragon vulnerabilities It was discovered that the Linux kernel did not properly initialize a Wake- on-Lan data structure. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2014-9900) It was discovered that the Linux kernel did not properly restrict access to /proc/iomem. A local attacker could use this to expose sensitive information. (CVE-2015-8944) Alexander Potapenko discovered a race condition in the Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2017-1000380) Li Qiang discovered that the DRM driver for VMware Virtual GPUs in the Linux kernel did not properly validate some ioctl arguments. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-7346) Jann Horn discovered that bpf in Linux kernel does not restrict the output of the print_bpf_insn function. A local attacker could use this to obtain sensitive address information. (CVE-2017-9150) Murray McAllister discovered that the DRM driver for VMware Virtual GPUs in the Linux kernel did not properly initialize memory. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2017-9605)

Affected Systems

  • ubuntulinux

    < 4.4.0-87.110

  • ubuntulinux-raspi2

    < 4.4.0-1065.73

  • ubuntulinux-snapdragon

    < 4.4.0-1067.72

References (7)