UBUNTU-CVE-2018-1108
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
02 / AFFECTED SOFTWARE
Affected packages
20 explicit affected versions
18 explicit affected versions
38 explicit affected versions
16 explicit affected versions
11 explicit affected versions
11 explicit affected versions
10 explicit affected versions
11 explicit affected versions
8 explicit affected versions
12 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
05 / REFERENCES
Further evidence
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1559
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=43838a23a05fbd13e47d750d3dfd77001536dd33
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8ef35c866f8862df074a49a93b0309725812dea8
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dc12baacb95f205948f64dc936a47d89ee110117
- https://ubuntu.com/security/CVE-2018-1108
- https://ubuntu.com/security/notices/USN-3752-1
- https://ubuntu.com/security/notices/USN-3752-2
- https://ubuntu.com/security/notices/USN-3752-3
- https://www.cve.org/CVERecord?id=CVE-2018-1108