USN-3540-2: Linux kernel (Xenial HWE) vulnerabilities
USN-3540-2: Linux kernel (Xenial HWE) vulnerabilities Ubuntu Security Notice USN-3540-2 22nd January, 2018 linux-lts-xenial, linux-aws vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were addressed in the Linux kernel. Software description linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-lts-xenial – Linux hardware enablement kernel from Xenial for Trusty Details USN-3540-1 addressed vulnerabilities in the Linux kernel for Ubuntu16.04 LTS. This update provides the corresponding updates for theLinux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS forUbuntu 14.04 LTS. Jann Horn discovered that microprocessors utilizing speculativeexecution and branch prediction may allow unauthorized memoryreads via sidechannel attacks. This flaw is known as Spectre. Alocal attacker could use this to expose sensitive information,including kernel memory. This update provides mitigations for thei386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.(CVE-2017-5715, CVE-2017-5753) [ more… ]