USN-3265-1: Linux kernel vulnerabilities
USN-3265-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3265-1 24th April, 2017 linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gke – Linux kernel for Google Container Engine (GKE) systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-snapdragon – Linux kernel for Snapdragon Processors Details It was discovered that a use-after-free flaw existed in the filesystemencryption subsystem in the Linux kernel. A local attacker could use thisto cause a denial of service (system crash). (CVE-2017-7374) Andrey Konovalov discovered an out-of-bounds access in the IPv6 GenericRouting Encapsulation (GRE) tunneling implementation in the Linux kernel.An attacker could use this to possibly expose sensitive information.(CVE-2017-5897) Andrey [ more… ]