Ubuntu security notices
USN-3293-1: Linux kernel vulnerabilities
USN-3293-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3293-1 16th May, 2017 linux, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel linux-raspi2 – Linux kernel for Raspberry Pi 2 Details Dmitry Vyukov discovered that KVM implementation in the Linux kernelimproperly emulated the VMXON instruction. A local attacker in a guest OScould use this to cause a denial of service (memory consumption) in thehost OS. (CVE-2017-2596) Dmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linuxkernel contained a stack-based buffer overflow. A local attacker withaccess to an sg device could use this to cause a denial of service (systemcrash) or possibly execute arbitrary code. (CVE-2017-7187) It was discovered that a NULL pointer dereference existed in the DirectRendering Manager [ more… ]