[USN-2663-1] Linux kernel vulnerabilities

Severity Medium
Affected Packages 9
CVEs 6

Several security issues were fixed in the kernel.

Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)

A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)

A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)

A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4002)

A division by zero error was discovered in the Linux kernel's Ozmo Devices
USB over WiFi host controller driver. A remote attacker could exploit this
flaw to cause a denial of service (system crash). (CVE-2015-4003)

Carl H Lunde discovered missing consistency checks in the Linux kernel's UDF
file system (CONFIG_UDF_FS). A local attacker could exploit this flaw to
cause a denial of service (system crash) by using a corrupted file system
image. (CVE-2015-4167)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-extra-3.13.0-57-generic?distro=trusty ubuntu linux-image-extra-3.13.0-57-generic < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-powerpc64-smp?distro=trusty ubuntu linux-image-3.13.0-57-powerpc64-smp < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-powerpc64-emb?distro=trusty ubuntu linux-image-3.13.0-57-powerpc64-emb < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-powerpc-smp?distro=trusty ubuntu linux-image-3.13.0-57-powerpc-smp < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-powerpc-e500mc?distro=trusty ubuntu linux-image-3.13.0-57-powerpc-e500mc < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-powerpc-e500?distro=trusty ubuntu linux-image-3.13.0-57-powerpc-e500 < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-lowlatency?distro=trusty ubuntu linux-image-3.13.0-57-lowlatency < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-generic?distro=trusty ubuntu linux-image-3.13.0-57-generic < 3.13.0-57.95 trusty
Affected pkg:deb/ubuntu/linux-image-3.13.0-57-generic-lpae?distro=trusty ubuntu linux-image-3.13.0-57-generic-lpae < 3.13.0-57.95 trusty
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...