USN-3099-1: Linux kernel vulnerabilities
USN-3099-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3099-1 11th October, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details Vladimír Beneš discovered an unbounded recursion in the VLAN and TEBGeneric Receive Offload (GRO) processing implementations in the Linuxkernel, A remote attacker could use this to cause a stack corruption,leading to a denial of service (system crash). (CVE-2016-7039) Marco Grassi discovered a use-after-free condition could occur in the TCPretransmit queue handling code in the Linux kernel. A local attacker coulduse this to cause a denial of service (system crash) or possibly executearbitrary code. (CVE-2016-6828) Pengfei Wang discovered a race condition in the s390 SCLP console driverfor the Linux kernel when handling ioctl()s. A local attacker could usethis [ more… ]