USN-3523-2: Linux kernel (HWE) vulnerabilities
USN-3523-2: Linux kernel (HWE) vulnerabilities Ubuntu Security Notice USN-3523-2 10th January, 2018 linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-hwe – Linux hardware enablement (HWE) kernel linux-oem – Linux kernel for OEM processors Details USN-3523-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.This update provides the corresponding updates for the LinuxHardware Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu16.04 LTS. Jann Horn discovered that microprocessors utilizing speculative executionand indirect branch prediction may allow unauthorized memory reads viasidechannel attacks. This flaw is known as Meltdown. A local attacker coulduse this to expose sensitive information, including kernel memory.(CVE-2017-5754) [ more… ]