Hide Forgot
Linux kernel built with the Kernel-based Virtual Machine(CONFIG_KVM) support is vulnerable to a use-after-free flaw. It could occur while creating devices, via ioctl('/dev/kvm', ...) calls. A user/process could use this flaw to crash the host kernel resulting in DoS or potentially escalate their privileges on a system. Upstream patch: --------------- -> https://git.kernel.org/linus/a0f1d21c1ccb1da66629627a74059dd7f5ac9c61 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/01/18/10
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1414507]
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
This issue was corrected in 4.8.13 kernels available across all current fedora releases on 2016-12-12.