USN-2909-1: Linux kernel (Utopic HWE) vulnerabilities
USN-2909-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu Security Notice USN-2909-1 22nd February, 2016 linux-lts-utopic vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-utopic – Linux hardware enablement kernel from Utopic Details halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,incorrectly propagated file attributes, including setuid. A localunprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS in the Linux kernel incorrectlypropagated security sensitive extended attributes, such as POSIX ACLs. Alocal unprivileged attacker could use this to gain privileges.(CVE-2016-1575) It was discovered that the Linux kernel's Filesystem in Userspace (FUSE)implementation did not handle initial zero length segments properly. Alocal attacker could use this to cause a denial of service (unkillabletask). (CVE-2015-8785) Update instructions The problem can be [ more… ]