[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-USN-3847-2":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T14:53:31.930Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":42,"duplicates":43,"related":44,"reserved_at":9,"published_at":52,"modified_at":53,"state":9,"summary":54,"references_raw":56,"kevs":92,"epss":9,"epss_history":93,"metrics":94,"affected":95},"USN-3847-2","linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities\n\nUSN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu\n16.04 LTS.\n\nIt was discovered that a race condition existed in the raw MIDI driver for\nthe Linux kernel, leading to a double free vulnerability. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2018-10902)\n\nIt was discovered that an integer overrun vulnerability existed in the\nPOSIX timers implementation in the Linux kernel. A local attacker could use\nthis to cause a denial of service. (CVE-2018-12896)\n\nNoam Rathaus discovered that a use-after-free vulnerability existed in the\nInfiniband implementation in the Linux kernel. An attacker could use this\nto cause a denial of service (system crash). (CVE-2018-14734)\n\nIt was discovered that the YUREX USB device driver for the Linux kernel did\nnot properly restrict user space reads or writes. A physically proximate\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-16276)\n\nIt was discovered that the BPF verifier in the Linux kernel did not\ncorrectly compute numeric bounds in some situations. A local attacker could\nuse this to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2018-18445)\n\nKanda Motohiro discovered that writing extended attributes to an XFS file\nsystem in the Linux kernel in certain situations could cause an error\ncondition to occur. A local attacker could use this to cause a denial of\nservice. (CVE-2018-18690)\n\nIt was discovered that an integer overflow vulnerability existed in the\nCDROM driver of the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-18710)\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40],{"_key":15},"CVE-2018-10902",{"_key":17},"CVE-2018-12896",{"_key":19},"CVE-2018-14734",{"_key":21},"CVE-2018-16276",{"_key":23},"CVE-2018-18445",{"_key":25},"CVE-2018-18690",{"_key":27},"CVE-2018-18710",{"_key":29},"UBUNTU-CVE-2018-10902",{"_key":31},"UBUNTU-CVE-2018-12896",{"_key":33},"UBUNTU-CVE-2018-14734",{"_key":35},"UBUNTU-CVE-2018-16276",{"_key":37},"UBUNTU-CVE-2018-18445",{"_key":39},"UBUNTU-CVE-2018-18690",{"_key":41},"UBUNTU-CVE-2018-18710",[],[],[45,46,47,48,49,50,51],{"_key":29},{"_key":33},{"_key":35},{"_key":37},{"_key":31},{"_key":39},{"_key":41},"2018-12-20T22:57:45.665071Z","2026-02-04T03:02:14.167309Z",{"cisa_kev":55,"cisa_ransomware":55,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[57,63,68,72,76,80,84,88],{"url":58,"sources":59,"tags":61},"https://ubuntu.com/security/notices/USN-3847-2",[60],"osv_ubuntu",[62],"Advisory",{"url":64,"sources":65,"tags":66},"https://ubuntu.com/security/CVE-2018-10902",[60],[67],"REPORT",{"url":69,"sources":70,"tags":71},"https://ubuntu.com/security/CVE-2018-12896",[60],[67],{"url":73,"sources":74,"tags":75},"https://ubuntu.com/security/CVE-2018-14734",[60],[67],{"url":77,"sources":78,"tags":79},"https://ubuntu.com/security/CVE-2018-16276",[60],[67],{"url":81,"sources":82,"tags":83},"https://ubuntu.com/security/CVE-2018-18445",[60],[67],{"url":85,"sources":86,"tags":87},"https://ubuntu.com/security/CVE-2018-18690",[60],[67],{"url":89,"sources":90,"tags":91},"https://ubuntu.com/security/CVE-2018-18710",[60],[67],[],[],[],[96,108,114,120],{"ecosystem":97,"name":98,"vendor":99,"product":98,"cpe_part":9,"purl_type":100,"purl_namespace":99,"purl_name":98,"source":9,"versions":101},"Ubuntu","linux-aws-hwe","ubuntu","deb",[102],{"version":103,"is_range":104,"range_type":105,"version_start":9,"version_start_type":9,"version_end":106,"version_end_type":107,"fixed_in":9},"lt4_15_0_1031_33~16_04_1",true,"ecosystem","4.15.0-1031.33~16.04.1","excluding",{"ecosystem":97,"name":109,"vendor":99,"product":109,"cpe_part":9,"purl_type":100,"purl_namespace":99,"purl_name":109,"source":9,"versions":110},"linux-azure",[111],{"version":112,"is_range":104,"range_type":105,"version_start":9,"version_start_type":9,"version_end":113,"version_end_type":107,"fixed_in":9},"lt4_15_0_1036_38~16_04_1","4.15.0-1036.38~16.04.1",{"ecosystem":97,"name":115,"vendor":99,"product":115,"cpe_part":9,"purl_type":100,"purl_namespace":99,"purl_name":115,"source":9,"versions":116},"linux-gcp",[117],{"version":118,"is_range":104,"range_type":105,"version_start":9,"version_start_type":9,"version_end":119,"version_end_type":107,"fixed_in":9},"lt4_15_0_1026_27~16_04_1","4.15.0-1026.27~16.04.1",{"ecosystem":97,"name":121,"vendor":99,"product":121,"cpe_part":9,"purl_type":100,"purl_namespace":99,"purl_name":121,"source":9,"versions":122},"linux-hwe",[123],{"version":124,"is_range":104,"range_type":105,"version_start":9,"version_start_type":9,"version_end":125,"version_end_type":107,"fixed_in":9},"lt4_15_0_43_46~16_04_1","4.15.0-43.46~16.04.1"]