- 
      PSBM-76970 Incorrect accounting of isolated pages in memcg_numa_isolate_pages().Isolated pages were accounted for incorrectly in memcg_numa_isolate_pages() in certain cases. As a result, some processes could hang forever.
 
- 
      CVE-2017-12193 Null pointer dereference due to incorrect node-splitting in assoc_array implementation.A flaw was found in the implementation of associative arrays in the Linux kernel. A null pointer dereference could happen in assoc_array_apply_edit() due to incorrect node splitting.
 https://bugzilla.redhat.com/show_bug.cgi?id=1501215
- 
      PSBM-76437 FUSE issues lots of small writes when resizing a file.Each resize issues invalidate_inode_pages2(), which triggers ultra slow synchronous writeback of all dirty pages.
 
- 
      PSBM-62094 sysinfo() returns 0 for uptime if called from a VZ7 container.sysinfo() returns 0 for uptime if called from a VZ7 container.
 
- 
      CVE-2017-15649 Use-after-free in af_packet.c.A vulnerability in fanout_add() in 'net/packet/af_packet.c' in the Linux kernel version 4.13.6 and older allows local users to gain privileges or cause a denial of service (kernel crash). A specially crafted sequence of system calls may trigger a race condition (involving fanout_add() and packet_do_bind() functions) that leads to a use-after-free.
 https://bugzilla.redhat.com/show_bug.cgi?id=1504574
- 
      PSBM-70021 Hung processes when trying to stop a container created on a storage partition.Hung processes when trying to stop a container created on a storage partition.
 
- 
      CVE-2016-8399 net: Out of bounds stack read in memcpy_fromiovec.A flaw was found in the Linux networking subsystem where a local attacker with CAP_NET_ADMIN capabilities could cause an out-of-bounds memory access by creating a smaller-than-expected ICMP header and sending to its destination via sendto().
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8399
- 
      CVE-2017-12190 Memory leak when merging buffers in SCSI IO vectors.It was found that in the Linux kernel through v4.14-rc5, bio_map_user_iov() and bio_unmap_user() in 'block/bio.c' do unbalanced pages refcounting if IO vector has small consecutive buffers belonging to the same page. bio_add_pc_page() merges them into one, but the page reference is never dropped, causing a memory leak and possible system lockup due to out-of-memory condition.
 https://bugzilla.redhat.com/show_bug.cgi?id=1495089
- 
      PSBM-75641 Kernel crash in rt6_ifdown().It was discovered that a specially crafted sequence of system calls could cause a kernel crash (general protection fault) in rt6_ifdown().
 https://bugzilla.redhat.com/show_bug.cgi?id=1492640
- 
      PSBM-75247 NULL pointer dereference in __task_pid_nr_ns().It was discovered that the value of task->pids[type].pid was actually read twice in __task_pid_nr_ns() rather than only once, due to compiler optimizations. As a result, a race condition could happen and that value could become NULL between these reads, leading to a kernel crash (NULL pointer dereference).
 
- 
      CVE-2017-12188 KVM, MMU: potential stack buffer overrun during page walks.Linux kernel built with the KVM virtualisation support (CONFIG_KVM), with nested virtualisation (nVMX) feature enabled (nested=1), is vulnerable to a stack buffer overflow issue. It could occur while traversing guest pagetable entries to resolve guest virtual address. A guest system could use this flaw to crash the host kernel resulting in DoS, or potentially execute arbitrary code on the host.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12188
- 
      CVE-2017-15274 Adding invalid keys with NULL payload but nonzero payload length leads to kernel crash.A flaw was discovered in the key management subsystem of the Linux kernel. It allowed to pass NULL payload with non-zero payload length as parameters to sys_add_key() and the KEYCTL_UPDATE operation of sys_keyctl(). A local unprivileged user could exploit this to cause a kernel crash (NULL pointer dereference).
 https://bugzilla.redhat.com/show_bug.cgi?id=1500391
- 
      PSBM-71536 autofs: unbalanced pid get/put operation in the error path in autofs4_fill_super().autofs: unbalanced pid get/put operation in the error path in autofs4_fill_super().
 
- 
      CVE-2017-15299 Incorrect updates of uninstantiated keys crash the kernel.It was discovered that the key management subsystem of the Linux kernel could perform incorrect update operations on uninstantiated keys. A local unprivileged user could exploit this flaw to cause a NULL pointer dereference in the kernel.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15299
- 
      CVE-2017-1000253 load_elf_binary() does not allocate sufficient space for the entire binary in some cases.A flaw was found in the way the Linux kernel loaded ELF executables. Provided that an application was built as Position Independent Executable (PIE), the loader could allow part of that application's data segment to map over the memory area reserved for its stack, potentially resulting in memory corruption. An unprivileged local user with access to SUID (or otherwise privileged) PIE binary could use this flaw to escalate their privileges on the system.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-1000253
- 
      CVE-2017-1000251 Buffer overflow in the native Bluetooth stack.It was discovered that a buffer overflow existed in the Bluetooth stack of the Linux kernel when handling L2CAP configuration responses. A physically proximate attacker could use this to cause a denial of service (system crash).
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-1000251
- 
      CVE-2017-12154 kvm: nVMX: L2 guest could access hardware (L0) CR8 register.If nested virtualisation (nVMX) feature is enabled in the kernel, L2 guest system could access the hardware CR8 register of the host(L0) and use that to crash the host system.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12154
- 
      CVE-2017-12192 Kernel crash due to missing error handling for negatively instantiated keys.An unprivileged user inside  a container can cause a denial of service (kernel crash in user_read() function) using a specially crafted sequence of system calls.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12192
- 
      PSBM-71747 netlink: fix an use-after-free issue for nlk groups.ChunYu Wang from Red Hat found a netlink use-after-free issue by syzkaller. Access to already freed memory (groups in struct netlink_sock) can cause host crash or memory corruption.
 
- 
      CVE-2017-14489 scsi: nlmsg not properly parsed in iscsi_if_rx function.The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-14489
- 
      CVE-2017-14106 net/ipv4: divide error in __tcp_select_window().A vulnerability was found in the Linux kernel. A privileged user inside a container can cause a denial of service (kernel crash due to a divide-by-zero error in __tcp_select_window()) using a specially crafted sequence of system calls.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-14106
- 
      CVE-2017-7558 Information leak due to out-of-bound reads in the implementation of SCTP.A kernel data leak due to an out-of-bound read was found in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions. It happens when these functions fill in sockaddr data structures used to export socket diagnostic information. As a result, up to 100 bytes of the slab data could be leaked to a userspace.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7558
- 
      PSBM-70321 Incorrect merge operations on IO requests leading to kernel crashes.It was discovered that the block layer of the kernel did not properly check for gaps in the IO requests being merged. In some cases, the resulting request could be incorrect, which lead to kernel crashes.
 
- 
      PSBM-70151 A container could not be stopped in certain situations because of an infinite loop in __get_user_pages().If transparent huge pages were enabled, certain processes could enter an infinite loop in __get_user_pages() and become unkillable preventing the container from stopping.
 
- 
      PSBM-69999 Kernel crashes in memcg_numa_migrate_write() during NUMA balancing.It was found that memcg_numa_isolate_pages() used unsafe operations with lists, which lead to kernel crashes in memcg_numa_migrate_write() during NUMA balancing.
 
- 
      PSBM-70063 Race on map->levels[] update in ploop.ploop could use inconsistent values for iblock and the corresponding delta for IO because of a race over map->levels[]. This could result in incorrect read and write operations for ploop devices.
 
- 
      CVE-2017-1000112 A race condition in the UDP Fragmentation Offload (UFO).Andrey Konovalov discovered a race condition in the UDP Fragmentation Offload (UFO) code in the Linux kernel. A local attacker could use this to cause a denial of service or execute arbitrary code.
 https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000112.html
- 
      CVE-2017-1000111 Heap out-of-bounds in AF_PACKET sockets.Andrey Konovalov discovered a race condition in AF_PACKET socket option handling code which may result in out-of-bounds accesses to the heap memory. A local unprivileged attacker could use this to cause a denial of service or possibly execute arbitrary code.
 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000111.html
- 
      CVE-2017-7533 A race between inotify_handle_event() and sys_rename().Fan Wu and Shixiong Zhao discovered a race condition between inotify events and vfs rename operations in the Linux kernel. An unprivileged local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.
 http://seclists.org/oss-sec/2017/q3/240
- 
      PSBM-68292 lseek(SEEK_DATA) and lseek(SEEK_HOLE) returned incorrect results on ext4 in some cases.It was discovered that lseek(SEEK_DATA) and lseek(SEEK_HOLE) returned incorrect values on ext4 FS in some cases, causing corruption of QCOW2 disk images used by VMs.
 
- 
      PSBM-69018 Division by zero in dcache_is_low().Division by zero in dcache_is_low().
 
- 
      PSBM-65033 venet: netdevice structures were not always freed (memory leak).venet: netdevice structures were not always freed (memory leak).
 
- 
      CVE-2017-11600 Out-of-bounds access via an XFRM_MSG_MIGRATE xfrm Netlink message.A vulnerability was found in the handling of xfrm Netlink messages. A privileged user inside a container could cause a denial of service (kernel crash) by sending a crafted Netlink message with type XFRM_MSG_MIGRATE to the kernel.
 http://seclists.org/bugtraq/2017/Jul/30
- 
      CVE-2017-7541 Possible heap buffer overflow in brcmf_cfg80211_mgmt_tx().Kernel memory corruption due to a buffer overflow was found in brcmf_cfg80211_mgmt_tx() function in Linux kernels from v3.9-rc1 to v4.13-rc1. The vulnerability can be triggered by sending a crafted NL80211_CMD_FRAME packet via netlink. An unprivileged local user could use this flaw to induce kernel memory corruption on the system, leading to a crash.
 https://bugzilla.redhat.com/show_bug.cgi?id=1473198
- 
      CVE-2017-7542 Integer overflow in ip6_find_1stfragopt().Integer overflow vulnerability in ip6_find_1stfragopt() function was found. Local attacker that has privileges to open raw sockets can cause infinite loop inside ip6_find_1stfragopt() function.
 https://bugzilla.redhat.com/show_bug.cgi?id=1473649
- 
      PSBM-68472 Kernel crash when accessing /proc/$PID/map_files.A data race was discovered in the implementation of /proc/$PID/map_files. A privileged user on the host could crash the kernel by using mmap and munmap for a file and simultaneously trying to access /proc/$PID/map_files.
 
- 
      PSBM-64050 sctp: potential kernel crash in sctp_wait_for_sndbuf().If sctp module was loaded on the host, a privileged user inside a container could make sctp listen on a socket in an inappropriate state, causing a kernel crash (use-after-free in sctp_wait_for_sndbuf()).
 
- 
      PSBM-68362 Kernel crash due to incorrect skb headroom calculation and missing checks.It was found that the kernel could crash (skb_under_panic) if an skb from a virtual (NETIF_F_VENET) device was processed in a particular networking configuration. The problem was caused by the incorrect skb headroom calculation and missing headroom checks.
 
- 
      PSBM-67513 Kernel crash in ploop due to the list corruption during parallel push backups.A data race was discovered in ploop, which could lead to the kernel crash due to the list corruption during parallel push backups.
 
- 
      PSBM-68052 The values shown in /proc/loadavg can be calculated incorrectly in some cases.A data race between calc_load_fold_active() and try_to_wake_up() was discovered. As a result of that race, the values shown in /proc/loadavg could be calculated incorrectly in some cases.
 
- 
      CVE-2017-11176 Use-after-free in sys_mq_notify().The implementation of mq_notify system call in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
 https://bugzilla.redhat.com/show_bug.cgi?id=1470659
- 
      PSBM-64752 ipv4: deadlock in ip_ra_control().A vulnerability was found in the implementation of setsockopt() operations in the Linux kernel. A privileged user inside a container could cause a DoS on the host (kernel deadlock in ip_ra_control() function) using a specially crafted sequence of system calls.
 
- 
      CVE-2017-7477 net: Heap overflow in skb_to_sgvec in macsec.c.Heap-based buffer overflow in drivers/net/macsec.c in the MACsec module in the Linux kernel through 4.10.12 allows attackers to cause a denial of service or possibly have unspecified other impact by leveraging the use of a MAX_SKB_FRAGS+1 size in conjunction with the NETIF_F_FRAGLIST feature, leading to an error in the skb_to_sgvec function.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7477
- 
      CVE-2017-8797 NFSv4 server does not properly validate layout type when processing NFSv4 pNFS LAYOUTGET operand.The NFSv4 server in the Linux kernel compiled with CONFIG_NFSD_PNFS enabled does not properly validate layout type when processing NFSv4 pNFS LAYOUTGET and GETDEVICEINFO operands. The attack payload fits to single one-way UDP packet. The provided input value is used for array dereferencing. This may lead to a remote DoS of [knfsd] and so to a soft-lockup of a whole system.
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-8797
- 
      PSBM-67263 Use after free in vxlan_dellink().A vulnerability was found in the implementation of vxlan interfaces in the Linux kernel. A privileged user inside a container was able to trigger a use-after-free in vxlan_dellink() function with a special sequence of operations with vxlan interfaces, which could result in a system crash or could possibly have other unspecified impact.
 
- 
      CVE-2017-9242 Kernel crash (out-of-bounds write) in __ip6_append_data().The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.
 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-9242.html
- 
      PSBM-67221 Kernel crash (general protection fault) in cleanup_timers().A vulnerability was found in the signal handling in the Linux kernel. A local unprivileged user may cause a kernel crash (general protection fault) in cleanup_timers() function by using rt_tgsigqueueinfo() system call with a specially crafted set of arguments.
 
- 
      PSBM-67300 Kernel crash (NULL pointer dereference) in list_lru_destroy().Kernel crash (NULL pointer dereference) in list_lru_destroy().
 
- 
      PSBM-67076 Kernel deadlocks in try_charge().When memcgroup reached memory limits, kernel may have entered an endless loop in try_charge(), and deadlocked.