It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container.
4.15.0-1202.217~14.04.14.15.0-251.2634.15.0-1202.2174.15.0-1186.2034.15.0-1175.1804.15.0-1155.1664.15.0-2111.1174.15.0-1148.1604.15.0-2094.100