[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-USN-3696-2":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":54,"duplicates":55,"related":56,"reserved_at":9,"published_at":67,"modified_at":68,"state":9,"summary":69,"references_raw":71,"kevs":119,"epss":9,"epss_history":120,"metrics":121,"affected":122},"USN-3696-2","linux-lts-xenial, linux-aws vulnerabilities\n\nUSN-3696-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nIt was discovered that an integer overflow existed in the perf subsystem of\nthe Linux kernel. A local attacker could use this to cause a denial of\nservice (system crash). (CVE-2017-18255)\n\nWei Fang discovered an integer overflow in the F2FS filesystem\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service. (CVE-2017-18257)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n\nIt was discovered that the wait4() system call in the Linux kernel did not\nproperly validate its arguments in some situations. A local attacker could\npossibly use this to cause a denial of service. (CVE-2018-10087)\n\nIt was discovered that the kill() system call implementation in the Linux\nkernel did not properly validate its arguments in some situations. A local\nattacker could possibly use this to cause a denial of service.\n(CVE-2018-10124)\n\nJulian Stecklina and Thomas Prescher discovered that FPU register states\n(such as MMX, SSE, and AVX registers) which are lazily restored are\npotentially vulnerable to a side channel attack. A local attacker could use\nthis to expose sensitive information. (CVE-2018-3665)\n\nJakub Jirasek discovered that multiple use-after-errors existed in the\nUSB/IP implementation in the Linux kernel. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5814)\n\nIt was discovered that an information leak vulnerability existed in the\nfloppy driver in the Linux kernel. A local attacker could use this to\nexpose sensitive information (kernel memory). (CVE-2018-7755)\n\nSeunghun Han discovered an information leak in the ACPI handling code in\nthe Linux kernel when handling early termination of ACPI table loading. A\nlocal attacker could use this to expose sensitive informal (kernel address\nlocations). (CVE-2017-13695)\n\nIt was discovered that a memory leak existed in the Serial Attached SCSI\n(SAS) implementation in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (memory exhaustion).\n(CVE-2018-10021)\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52],{"_key":15},"CVE-2017-13695",{"_key":17},"CVE-2017-18255",{"_key":19},"CVE-2017-18257",{"_key":21},"CVE-2018-1000204",{"_key":23},"CVE-2018-10021",{"_key":25},"CVE-2018-10087",{"_key":27},"CVE-2018-10124",{"_key":29},"CVE-2018-3665",{"_key":31},"CVE-2018-5814",{"_key":33},"CVE-2018-7755",{"_key":35},"UBUNTU-CVE-2017-13695",{"_key":37},"UBUNTU-CVE-2017-18255",{"_key":39},"UBUNTU-CVE-2017-18257",{"_key":41},"UBUNTU-CVE-2018-1000204",{"_key":43},"UBUNTU-CVE-2018-10021",{"_key":45},"UBUNTU-CVE-2018-10087",{"_key":47},"UBUNTU-CVE-2018-10124",{"_key":49},"UBUNTU-CVE-2018-3665",{"_key":51},"UBUNTU-CVE-2018-5814",{"_key":53},"UBUNTU-CVE-2018-7755",[],[],[57,58,59,60,61,62,63,64,65,66],{"_key":39},{"_key":51},{"_key":35},{"_key":37},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":53},"2018-07-02T19:45:37.331006Z","2026-02-04T03:08:36.314230Z",{"cisa_kev":70,"cisa_ransomware":70,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[72,78,83,87,91,95,99,103,107,111,115],{"url":73,"sources":74,"tags":76},"https://ubuntu.com/security/notices/USN-3696-2",[75],"osv_ubuntu",[77],"Advisory",{"url":79,"sources":80,"tags":81},"https://ubuntu.com/security/CVE-2017-13695",[75],[82],"REPORT",{"url":84,"sources":85,"tags":86},"https://ubuntu.com/security/CVE-2017-18255",[75],[82],{"url":88,"sources":89,"tags":90},"https://ubuntu.com/security/CVE-2017-18257",[75],[82],{"url":92,"sources":93,"tags":94},"https://ubuntu.com/security/CVE-2018-3665",[75],[82],{"url":96,"sources":97,"tags":98},"https://ubuntu.com/security/CVE-2018-5814",[75],[82],{"url":100,"sources":101,"tags":102},"https://ubuntu.com/security/CVE-2018-7755",[75],[82],{"url":104,"sources":105,"tags":106},"https://ubuntu.com/security/CVE-2018-10021",[75],[82],{"url":108,"sources":109,"tags":110},"https://ubuntu.com/security/CVE-2018-10087",[75],[82],{"url":112,"sources":113,"tags":114},"https://ubuntu.com/security/CVE-2018-10124",[75],[82],{"url":116,"sources":117,"tags":118},"https://ubuntu.com/security/CVE-2018-1000204",[75],[82],[],[],[],[123,135],{"ecosystem":124,"name":125,"vendor":126,"product":125,"cpe_part":9,"purl_type":127,"purl_namespace":126,"purl_name":125,"source":9,"versions":128},"Ubuntu","linux-aws","ubuntu","deb",[129],{"version":130,"is_range":131,"range_type":132,"version_start":9,"version_start_type":9,"version_end":133,"version_end_type":134,"fixed_in":9},"lt4_4_0_1024_25",true,"ecosystem","4.4.0-1024.25","excluding",{"ecosystem":124,"name":136,"vendor":126,"product":136,"cpe_part":9,"purl_type":127,"purl_namespace":126,"purl_name":136,"source":9,"versions":137},"linux-lts-xenial",[138],{"version":139,"is_range":131,"range_type":132,"version_start":9,"version_start_type":9,"version_end":140,"version_end_type":134,"fixed_in":9},"lt4_4_0_130_156~14_04_1","4.4.0-130.156~14.04.1"]