ISOMAN

Filtered CVEs

omnios-r151058.iso CVEs

CVEs linked through OmniOS r151058.

Release Context

  1. OmniOS · r151058

3 CVEs

  1. CVE-2020-27678
    CRITICAL · CVSS 9.8 ·

    An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.

  2. CVE-2020-24718
    HIGH · CVSS 8.2 ·

    bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

  3. CVE-2019-19396
    HIGH · CVSS 7.5 ·

    illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.