SB2017091814 - Amazon Linux AMI update for kernel
Published: September 18, 2017
Security Bulletin ID
SB2017091814
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Privilege escalation (CVE-ID: CVE-2017-12134)
The vulnerability allows a local attacker on a Linux-based guest system to gain elevated privileges on the host system.The weakness exists due to aa flaw in merging adjacent block IO requests. A local attacker on the guest system can incorrectly access memory during block stream processing to obtain potentially sensitive information or gain elevated privileges on the host system.
Remediation
Install update from vendor's website.