
USN-4007-2: Linux kernel (HWE) vulnerability
USN-4007-2: Linux kernel (HWE) vulnerability linux-aws-hwe, linux-hwe, linux-oracle vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary A system hardening measure could be bypassed. Software Description linux-aws-hwe – Linux kernel for Amazon Web Services (AWS-HWE) systems linux-hwe – Linux hardware enablement (HWE) kernel linux-oracle – Linux kernel for Oracle Cloud systems Details USN-4007-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu 16.04 LTS. Federico Manuel Bento discovered that the Linux kernel did not properly apply Address Space Layout Randomization (ASLR) in some situations for setuid a.out binaries. A local attacker could use this to improve the chances of exploiting an existing vulnerability in a setuid a.out binary. As a hardening measure, this [ more… ]