No Image

USN-3053-1: Linux kernel (Vivid HWE) vulnerabilities

2016-08-10 KENNETH 0

USN-3053-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu Security Notice USN-3053-1 10th August, 2016 linux-lts-vivid vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-vivid – Linux hardware enablement kernel from Vivid for Trusty Details A missing permission check when settings ACLs was discovered in nfsd. Alocal user could exploit this flaw to gain access to any file by setting anACL. (CVE-2016-1237) It was discovered that the keyring implementation in the Linux kernel didnot ensure a data structure was initialized before referencing it after anerror condition occurred. A local attacker could use this to cause a denialof service (system crash). (CVE-2016-4470) Sasha Levin discovered that a use-after-free existed in the percpuallocator in the Linux kernel. A local attacker could use this to cause adenial [ more… ]

No Image

USN-3052-1: Linux kernel vulnerabilities

2016-08-10 KENNETH 0

USN-3052-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3052-1 10th August, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details It was discovered that the keyring implementation in the Linux kernel didnot ensure a data structure was initialized before referencing it after anerror condition occurred. A local attacker could use this to cause a denialof service (system crash). (CVE-2016-4470) Kangjie Lu discovered an information leak in the netlink implementation ofthe Linux kernel. A local attacker could use this to obtain sensitiveinformation from kernel memory. (CVE-2016-5243) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: linux-image-3.13.0-93-lowlatency 3.13.0-93.140 linux-image-3.13.0-93-powerpc-e500mc 3.13.0-93.140 linux-image-3.13.0-93-powerpc64-emb 3.13.0-93.140 linux-image-3.13.0-93-powerpc-e500 3.13.0-93.140 linux-image-3.13.0-93-generic 3.13.0-93.140 linux-image-3.13.0-93-powerpc-smp 3.13.0-93.140 linux-image-3.13.0-93-generic-lpae [ more… ]

No Image

USN-3051-1: Linux kernel (Trusty HWE) vulnerabilities

2016-08-10 KENNETH 0

USN-3051-1: Linux kernel (Trusty HWE) vulnerabilities Ubuntu Security Notice USN-3051-1 10th August, 2016 linux-lts-trusty vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-trusty – Linux hardware enablement kernel from Trusty for Precise Details It was discovered that the keyring implementation in the Linux kernel didnot ensure a data structure was initialized before referencing it after anerror condition occurred. A local attacker could use this to cause a denialof service (system crash). (CVE-2016-4470) Kangjie Lu discovered an information leak in the netlink implementation ofthe Linux kernel. A local attacker could use this to obtain sensitiveinformation from kernel memory. (CVE-2016-5243) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: linux-image-3.13.0-93-generic-lpae 3.13.0-93.140~precise1 linux-image-3.13.0-93-generic 3.13.0-93.140~precise1 To [ more… ]

No Image

USN-3050-1: Linux kernel (OMAP4) vulnerabilities

2016-08-10 KENNETH 0

USN-3050-1: Linux kernel (OMAP4) vulnerabilities Ubuntu Security Notice USN-3050-1 10th August, 2016 linux-ti-omap4 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-ti-omap4 – Linux kernel for OMAP4 Details Ben Hawkes discovered that the Linux netfilter implementation did notcorrectly perform validation when handling IPT_SO_SET_REPLACE events. Alocal unprivileged attacker could use this to cause a denial of service(system crash) or possibly execute arbitrary code with administrativeprivileges. (CVE-2016-3134) Vitaly Kuznetsov discovered that the Linux kernel did not properly suppresshugetlbfs support in X86 paravirtualized guests. An attacker in the guestOS could cause a denial of service (guest system crash). (CVE-2016-3961) It was discovered that the keyring implementation in the Linux kernel didnot ensure a data structure was initialized before referencing it after anerror condition occurred. A [ more… ]

No Image

USN-3049-1: Linux kernel vulnerabilities

2016-08-10 KENNETH 0

USN-3049-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3049-1 10th August, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details Ben Hawkes discovered that the Linux netfilter implementation did notcorrectly perform validation when handling IPT_SO_SET_REPLACE events. Alocal unprivileged attacker could use this to cause a denial of service(system crash) or possibly execute arbitrary code with administrativeprivileges. (CVE-2016-3134) Vitaly Kuznetsov discovered that the Linux kernel did not properly suppresshugetlbfs support in X86 paravirtualized guests. An attacker in the guestOS could cause a denial of service (guest system crash). (CVE-2016-3961) It was discovered that the keyring implementation in the Linux kernel didnot ensure a data structure was initialized before referencing it after anerror condition occurred. A local attacker could [ more… ]