AVG-323

Package linux
Status Fixed
Severity Medium
Type multiple issues
Affected 4.11.6-3
Fixed 4.12.1-1
Current 4.19.2.arch1-1 [testing]
4.19.1.arch1-1 [core]
Ticket None
Created Thu Jun 22 14:57:36 2017
Issue Severity Remote Type Description
CVE-2017-1000379 Medium No Access restriction bypass
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing...
CVE-2017-1000365 Medium No Insufficient validation
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does...
References
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt