USN-3469-2: Linux kernel (Xenial HWE) vulnerabilities
USN-3469-2: Linux kernel (Xenial HWE) vulnerabilities Ubuntu Security Notice USN-3469-2 31st October, 2017 linux-lts-xenial vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-lts-xenial – Linux hardware enablement kernel from Xenial for Trusty Details USN-3469-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04LTS. This update provides the corresponding updates for the LinuxHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu14.04 LTS. Anthony Perard discovered that the Xen virtual block driver did notproperly initialize some data structures before passing them to user space.A local attacker in a guest VM could use this to expose sensitiveinformation from the host OS or other guest VMs. (CVE-2017-10911) Bo Zhang discovered that the netlink wireless configuration interface inthe Linux kernel did not properly validate attributes [ more… ]