[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-3582-2 -- linux-image

ID: oval:org.secpod.oval:def:703994Date: (C)2018-02-23   (M)2024-04-17
Class: PATCHFamily: unix




linux-aws: Linux kernel for Amazon Web Services systems - linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty Details: USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS. Mohamed Ghannam discovered that the IPv4 raw socket implementation in the Linux kernel contained a race condition leading to uninitialized pointer usage. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Laurent Guerby discovered that the mbcache feature in the ext2 and ext4 filesystems in the Linux kernel improperly handled xattr block caching. A local attacker could use this to cause a denial of service. Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel did not properly track reference counts when merging buffers. A local attacker could use this to cause a denial of service . ChunYu Wang discovered that a use-after-free vulnerability existed in the SCTP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code, Mohamed Ghannam discovered a use-after-free vulnerability in the DCCP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. USN-3540-2 mitigated CVE-2017-5715 for the amd64 architecture in Ubuntu 14.04 LTS. This update provides the compiler-based retpoline kernel mitigation for the amd64 and i386 architectures. Original advisory Several security issues were fixed in the Linux kernel.

Platform:
Ubuntu 14.04
Product:
linux-image
linux-image-4.4
linux-image-generic-4.4
linux-image-aws-4.4
linux-image-lowlatency-4.4
Reference:
USN-3582-2
CVE-2017-17712
CVE-2015-8952
CVE-2017-12190
CVE-2017-15115
CVE-2017-8824
CVE-2017-5715
CVE    6
CVE-2017-12190
CVE-2017-15115
CVE-2017-17712
CVE-2017-8824
...
CPE    6
cpe:/a:linux:linux_image_metapackage
cpe:/a:linux:linux_image_aws:4.4
cpe:/a:linux:linux_image:4.4
cpe:/a:linux:linux_image_generic:4.4
...

© SecPod Technologies