USN-3338-2: Linux kernel regression
USN-3338-2: Linux kernel regression Ubuntu Security Notice USN-3338-2 29th June, 2017 linux regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel Details USN-3338-1 fixed vulnerabilities in the Linux kernel. However, the fixfor CVE-2017-1000364 introduced regressions for some Java applications.This update addresses the issue. We apologize for the inconvenience. Original advisory details: It was discovered that the stack guard page for processes in the Linux kernel was not sufficiently large enough to prevent overlapping with the heap. An attacker could leverage this with another vulnerability to execute arbitrary code and gain administrative privileges (CVE-2017-1000364) Jesse Hertz and Tim Newsham discovered that the Linux netfilter implementation did not correctly perform validation when handling 32 bit compatibility IPT_SO_SET_REPLACE events on 64 [ more… ]