Ubuntu security notices
USN-3291-2: Linux kernel vulnerabilities
USN-3291-2: Linux kernel vulnerabilities Ubuntu Security Notice USN-3291-2 17th May, 2017 linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gke – Linux kernel for Google Container Engine (GKE) systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-snapdragon – Linux kernel for Snapdragon Processors Details USN-3291-1 fixed vulnerabilities in the generic Linux kernel.This update provides the corresponding updates for the Linux kernelbuilt for specific processors and cloud environments. Dmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linuxkernel contained a stack-based buffer overflow. A local attacker withaccess to an sg device could use this to cause a denial of service (systemcrash) or possibly execute arbitrary code. [ more… ]