Wednesday, February 3, 2016

F24 System Wide Change: GNOME 3.20

= Proposed System Wide Change: GNOME 3.20 =
https://fedoraproject.org/wiki/Changes/GNOME3.20

Change owner(s):
* Kalev Lember <klember AT redhat DOT com>

Update GNOME to the latest upstream release, 3.20

== Detailed Description ==
The new features for 3.20 include:
* Graphical System Upgrades
* Cantarell font improvements
* Shortcuts windows
* New Mouse and Touchpad Settings
* Improved CSS theming for GTK+ apps

== Scope ==
Proposal owners:
* Keep existing GNOME packages updated
* Follow upstream module changes
* Package new applications and new dependencies of existing GNOME
packages for GNOME 3.20

Other developers: N/A

Release engineering: N/A

Policies and guidelines: N/A
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
http://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

F24 Self Contained Change: Graphical System Upgrades

= Proposed Self Contained Change: Graphical System Upgrades =
https://fedoraproject.org/wiki/Changes/GraphicalSystemUpgrades

Change owner(s):
* Kalev Lember < klember AT redhat DOT com >

Add support for performing system upgrades to a newer Fedora release
through GNOME Software.

== Detailed Description ==
We'll implement a graphical user interface for system upgrades. The
implementation will use PackageKit and the libhif stack as a backend
and GNOME Software as a frontend. First supported version is going to
be Fedora 23->24 upgrades.

== Scope ==
Proposal owners:
* Implement this change

Other developers: N/A (not a System Wide Change)

Release engineering: N/A (not a System Wide Change)

List of deliverables: N/A (not a System Wide Change)

Policies and guidelines: N/A (not a System Wide Change)

Trademark approval: N/A (not needed for this Change)
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
http://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

[USN-2891-1] QEMU vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWsf42AAoJEGVp2FWnRL6TILEP/1kHH4woxh4Dc9XQaT3kTxSJ
wuUbbWu7FTvM+6N8SW6Hra4LatkU79OsNKtyYndmb552c0Op69YmsxMs0jRenZ8S
mEbkRi2Ps2ePis09UtRZni0kl1uZQbN7GmkhVlZKsXvfElg1omSdnGf83yvkM/pn
QZXRoroCG6riJfwrw6BsBhW/+94Csjz+GaHfmukyqpszw4NMeOrDdbrrxFZ+pNVQ
Cd5UxkgJjpmCzpXEKqyW3KiQxB1prinhsJMyfP2XPXu+2Y4zwFcLP/VxoIESP41g
0md6PhfbfLFUyeJR8e0hpGlKbe9Z1wJhB1TK2Tdp+OHDbjv8KNMgYN4HFCofEkjY
x9xtcTQ7wKE496dWN8pcLIq78DarvKcS6X4MSyThfQKSOJQDP9RU+MKjDJvtJO/y
r48lBXB3Nn9ZWPztboq+E+u6JLosWtLMR42EsZvOxq1gAiAYiU+8vRkgUcCALBZP
lL3klOxWiBNFLGyHrCWSKVRhdXE2ujrXqZktCawr12780pTq6hiWcyT9HW8nNoIf
TvwpC/iE+lbA8LtIJoFhTWBYaLiaHx5RafxPJNYmUPZftrJnueN8WV4wj6viDqtG
aO6yBs1lgb76zzyqaQZWg4/flEHiGMKIgObNRe0ssRDN1/Rdix/rqzPURRwVEEsC
R+Sj3VT7g/gvmvoKe7po
=6yE0
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2891-1
February 03, 2016

qemu, qemu-kvm vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in QEMU.

Software Description:
- qemu: Machine emulator and virtualizer
- qemu-kvm: Machine emulator and virtualizer

Details:

Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2015-7549)

Lian Yihan discovered that QEMU incorrectly handled the VNC server. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service. (CVE-2015-8504)

Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)

Qinghao Tang discovered that QEMU incorrectly handled USB EHCI emulation
support. An attacker inside the guest could use this issue to cause QEMU to
consume resources, resulting in a denial of service. (CVE-2015-8558)

Qinghao Tang discovered that QEMU incorrectly handled the vmxnet3 device.
An attacker inside the guest could use this issue to cause QEMU to consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8567, CVE-2015-8568)

Qinghao Tang discovered that QEMU incorrectly handled SCSI MegaRAID SAS HBA
emulation. An attacker inside the guest could use this issue to cause QEMU
to crash, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8613)

Ling Liu discovered that QEMU incorrectly handled the Human Monitor
Interface. A local attacker could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2015-8619, CVE-2016-1922)

David Alan Gilbert discovered that QEMU incorrectly handled the Q35 chipset
emulation when performing VM guest migrations. An attacker could use this
issue to cause QEMU to crash, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8666)

Ling Liu discovered that QEMU incorrectly handled the NE2000 device. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. (CVE-2015-8743)

It was discovered that QEMU incorrectly handled the vmxnet3 device. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2015-8744, CVE-2015-8745)

Qinghao Tang discovered that QEMU incorrect handled IDE AHCI emulation. An
attacker inside the guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2016-1568)

Donghai Zhu discovered that QEMU incorrect handled the firmware
configuration device. An attacker inside the guest could use this issue to
cause a denial of service, or possibly execute arbitrary code on the host
as the user running the QEMU process. In the default installation, when
QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2016-1714)

It was discovered that QEMU incorrectly handled the e1000 device. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. (CVE-2016-1981)

Zuozhi Fzz discovered that QEMU incorrectly handled IDE AHCI emulation. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 15.10.
(CVE-2016-2197)

Zuozhi Fzz discovered that QEMU incorrectly handled USB EHCI emulation. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2016-2198)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
qemu-system 1:2.3+dfsg-5ubuntu9.2
qemu-system-aarch64 1:2.3+dfsg-5ubuntu9.2
qemu-system-arm 1:2.3+dfsg-5ubuntu9.2
qemu-system-mips 1:2.3+dfsg-5ubuntu9.2
qemu-system-misc 1:2.3+dfsg-5ubuntu9.2
qemu-system-ppc 1:2.3+dfsg-5ubuntu9.2
qemu-system-sparc 1:2.3+dfsg-5ubuntu9.2
qemu-system-x86 1:2.3+dfsg-5ubuntu9.2

Ubuntu 14.04 LTS:
qemu-system 2.0.0+dfsg-2ubuntu1.22
qemu-system-aarch64 2.0.0+dfsg-2ubuntu1.22
qemu-system-arm 2.0.0+dfsg-2ubuntu1.22
qemu-system-mips 2.0.0+dfsg-2ubuntu1.22
qemu-system-misc 2.0.0+dfsg-2ubuntu1.22
qemu-system-ppc 2.0.0+dfsg-2ubuntu1.22
qemu-system-sparc 2.0.0+dfsg-2ubuntu1.22
qemu-system-x86 2.0.0+dfsg-2ubuntu1.22

Ubuntu 12.04 LTS:
qemu-kvm 1.0+noroms-0ubuntu14.27

After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2891-1
CVE-2015-7549, CVE-2015-8504, CVE-2015-8550, CVE-2015-8558,
CVE-2015-8567, CVE-2015-8568, CVE-2015-8613, CVE-2015-8619,
CVE-2015-8666, CVE-2015-8743, CVE-2015-8744, CVE-2015-8745,
CVE-2016-1568, CVE-2016-1714, CVE-2016-1922, CVE-2016-1981,
CVE-2016-2197, CVE-2016-2198

Package Information:
https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2
https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22
https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.27

[opensuse-announce] openSUSE 13.1 has reached end of SUSE support - 13.1 Evergreen goes on

Hi all,

with the release of systemd on February 3rd, 2016 the SUSE sponsored
maintenance of openSUSE 13.1 has ended.

openSUSE 13.1 is now officially discontinued and out of support by SUSE.

openSUSE 13.1 now will be continued to be maintained by the Evergreen
community team. Their wikipage is on http://en.opensuse.org/Evergreen,
please check it out for more information.

Here are some statistics:

openSUSE 13.1 was released on November 19th 2013, making it ca. 26
months of security and bugfix support.

Some statistics on the released patches (compared to 12.3):

Total updates: 1242 (+331)
Security: 617 (+148) 469
Recommended: 619 (+179)
Optional: 5 (+4)
Feature: 1 (0)

Fixed CVE-entries: 2312 (+730) 1582
Fixed Bugs (overall): 3029 (+1167) 1862

A huge thanks to our awesome packagers, community and all involved
people, who made the next great release possible!

Also a special thanks to the Evergreen-team which keeps 13.1 alive!


Your maintenance- and security-team

--
Benjamin Brunner <bbrunner@suse.com>,
SUSE MaintenanceSecurity
SUSE LINUX GmbH, GF: Felix Imendörffer, Jane Smithard, Graham Norton,
HRB 21284
(AG Nürnberg)
--
To unsubscribe, e-mail: opensuse-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-announce+help@opensuse.org

Tuesday, February 2, 2016

[announce] NYC*BUG Wednesday: Isaac Levy on 'Shell-Fu'

Upcoming meetings and events, including tomorrow's monthly meeting.

* February 3 "shell-fu" Isaac (.ike) Levy

* March 2 "Discussion of the Past and Future of PID 1 on BSD" Raul Cuza
Raul's meeting is something of a reply to reaffirmation of the BSD
init/rc systems, in the face of systemd

* April 6 "Debugging with llvm" John Wolfe

* May 4 "Urchin: Putting an End to Sloppy Shell Code" Thomas Levine

* June 15 "Adventures in HardenedBSD" Shawn Webb
Shawn will be coming up from Maryland for this meeting. Note the
date which was set as to not conflict with BSDCan

* July 6 "Meet the Smallest BSDs: RetroBSD and LiteBSD" Brian Callahan

* August 3 A *BSD Installfest
This installfest will happen after HOPE, and is a great meeting to
publicize at HOPE. We should have fliers for this event at HOPE

* Sept 7 "Teaching FreeBSD" George Neville-Neil

Also note these other upcoming events:

* Tokyo, Japan: AsiaBSCon, March 10-13

* Ottawa, Canada: BSDCan, June 10-11
with tutorials and the dev summit beforehand

* New York, NY: HOPE (Hackers on Planet Earth), July 22-24
a great opportunity for more popular BSD-related presentations

************************

Feb 3: Isaac Levy on "shell-fu"
18:45, Stone Creek Bar & Lounge: 140 E 27th St

Abstract

shell-fu in 3 short talks

To say everything starts with the shell, is quite an understatement.
Portable shell programming does not have to be painful, exposing the raw
power of UNIX with shell can even be fun.

This talk is relevant for expert and novice alike, aimed at anyone who
uses UNIX systems.

Not the 'shell tricks' variety of talk, but a language discussion
focused on portability, and showing off how simple and profoundly
powerful portable shell can be.

We will cover:

the 3 finger claw technique
using atomic filesystem operations
general shell-fu, input and variable handling

There is always something amazing to learn about sh(1).

Speaker Bio

Isaac (.ike) Levy is a crusty UNIX Hacker.

A long-time community contributor to the *BSD's, ike is obsessed with
high-availability and redundant networked servers systems, mostly
because he likes to sleep at night. Standing on the shoulders of giants,
his background includes partnering to run a Virtual Server ISP before
anyone called it a cloud, as well as having a long history building
internet-facing infrastructure with UNIX systems.

.ike has been a part of NYC*BUG since it was first launched in January
2004. He was a long-time member of the Lower East Side Mac Unix User
Group, and is still in denial that this group no longer exists. He has
spoken frequently on a number of UNIX and internet security topics at
various venues, particularly on the topic of FreeBSD's jail(8).

_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce

Fedora 24 Bugzilla Rawhide rebase

Greetings,

This e-mail is intended to inform you about the upcoming Bugzilla changes
happening on 2016-Feb-23 (Rawhide bug rebase) and what you need to do,
if anything.

We will be automatically changing the version for most rawhide bugs to
Fedora 24.
This will result in regular bugs reported against rawhide during the Fedora 24
development cycle being changed to version '24' instead of their current
assignment, 'rawhide'. This is to align with the branching of Fedora 24 from
rawhide and to more accurately tell where in the lineage of releases the bug was
last reported.

Note that this procedure does not apply to bugs that are open for the "Package
Review" component or bugs that have the ''FutureFeature'' or
''Tracking'' keywords
set. These will stay open as rawhide bugs indefinitely.

If you do not want your bugs changed to version '24', add the ''FutureFeature''
keyword. If you need help changing a large amount of bugs manually, we'd be glad
to help.

The process was re-approved by FESCo https://fedorahosted.org/fesco/ticket/1096.
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
http://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

REMINDER: Changes submission deadline for Fedora 24 is today

Hi everyone!

Today we have Fedora 24 Changes submission deadline [1]. No more
System Wide Changes should be accepted for this release.
Alpha release is currently planned on March, the 22nd.

In case you'll need any help with your Change proposals, feel free to
contact me.

[1] https://fedoraproject.org/wiki/Releases/24/Schedule

Best Regards,
Jan
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
http://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

[opensuse-announce] Re: openSUSE board election 2016 results

On 2 February 2016 at 07:29, Martin Pluskal <martin@pluskal.org> wrote:
> Hello
>
> it is my pleasure to announce results of openSUSE board elections [1]:
> - we had 147 people voting
> - number of votes for candidates:
> Tomáš Chvátal 105 votes
> Bryan Lunduke 89 votes
> Gertjan Lettink 89 votes
> Manu Gupta 51 votes
> Efstathios Iosifidis 49 votes
>
> Thus new members of board are Tomáš Chvátal, Bryan Lunduke and Gertjan Lettink
> who will replace Andrew Wafaa, Bruno Friedman and Robert Schweikert.
>
> I would like to use this opportunity to thank all members for voting,
> candidates for standing for elections and last but not least Bruno, Andy and
> Robert for doing great job while serving in openSUSE board.
>
> Have a lot of fun
>
> Martin Pluskal
>
> 1. https://connect.opensuse.org/pg/polls/read/pluskalm/49480/opensuse-board-election-20152016

As an outgoing member of the Board, I would like to congratulate
Tomáš, Bryen and Gertjan on being elected. I'm confident that you will
do the openSUSE community proud. I would also like to commiserate Manu
and Stathis, don't feel disheartened and I look forward to your
ongoing contributions.

Regards,
Andy
--
To unsubscribe, e-mail: opensuse-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-announce+help@opensuse.org

[opensuse-announce] openSUSE board election 2016 results

Hello

it is my pleasure to announce results of openSUSE board elections [1]:
- we had 147 people voting
- number of votes for candidates:
Tomáš Chvátal 105 votes
Bryan Lunduke 89 votes
Gertjan Lettink 89 votes
Manu Gupta 51 votes
Efstathios Iosifidis 49 votes

Thus new members of board are Tomáš Chvátal, Bryan Lunduke and Gertjan Lettink
who will replace Andrew Wafaa, Bruno Friedman and Robert Schweikert.

I would like to use this opportunity to thank all members for voting,
candidates for standing for elections and last but not least Bruno, Andy and
Robert for doing great job while serving in openSUSE board.

Have a lot of fun

Martin Pluskal

1. https://connect.opensuse.org/pg/polls/read/pluskalm/49480/opensuse-board-election-20152016

Monday, February 1, 2016

[USN-2890-3] Linux kernel (Raspberry Pi 2) vulnerabilities

==========================================================================
Ubuntu Security Notice USN-2890-3
February 02, 2016

linux-raspi2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-raspi2: Linux kernel for Raspberry Pi 2

Details:

It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)

It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)

It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)

Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7990)

It was discovered that the Btrfs implementation in the Linux kernel
incorrectly handled compressed inline extants on truncation. A local
attacker could use this to expose sensitive information. (CVE-2015-8374)

郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2015-8543)

Dmitry Vyukov discovered that the pptp implementation in the Linux kernel
did not verify an address length when setting up a socket. A local attacker
could use this to craft an application that exposed sensitive information
from kernel memory. (CVE-2015-8569)

David Miller discovered that the Bluetooth implementation in the Linux
kernel did not properly validate the socket address length for Synchronous
Connection-Oriented (SCO) sockets. A local attacker could use this to
expose sensitive information. (CVE-2015-8575)

It was discovered that the netfilter Network Address Translation (NAT)
implementation did not ensure that data structures were initialized when
handling IPv4 addresses. An attacker could use this to cause a denial of
service (system crash). (CVE-2015-8787)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
linux-image-4.2.0-1022-raspi2 4.2.0-1022.29

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2890-3
http://www.ubuntu.com/usn/usn-2890-1
CVE-2013-7446, CVE-2015-7513, CVE-2015-7550, CVE-2015-7990,
CVE-2015-8374, CVE-2015-8543, CVE-2015-8569, CVE-2015-8575,
CVE-2015-8787

Package Information:
https://launchpad.net/ubuntu/+source/linux-raspi2/4.2.0-1022.29

[USN-2890-2] Linux kernel (Wily HWE) vulnerabilities

==========================================================================
Ubuntu Security Notice USN-2890-2
February 02, 2016

linux-lts-wily vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-wily: Linux hardware enablement kernel from Wily

Details:

It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)

It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)

It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)

Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7990)

It was discovered that the Btrfs implementation in the Linux kernel
incorrectly handled compressed inline extants on truncation. A local
attacker could use this to expose sensitive information. (CVE-2015-8374)

郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2015-8543)

Dmitry Vyukov discovered that the pptp implementation in the Linux kernel
did not verify an address length when setting up a socket. A local attacker
could use this to craft an application that exposed sensitive information
from kernel memory. (CVE-2015-8569)

David Miller discovered that the Bluetooth implementation in the Linux
kernel did not properly validate the socket address length for Synchronous
Connection-Oriented (SCO) sockets. A local attacker could use this to
expose sensitive information. (CVE-2015-8575)

It was discovered that the netfilter Network Address Translation (NAT)
implementation did not ensure that data structures were initialized when
handling IPv4 addresses. An attacker could use this to cause a denial of
service (system crash). (CVE-2015-8787)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-4.2.0-27-generic 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-generic-lpae 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-lowlatency 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc-e500mc 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc-smp 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc64-emb 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc64-smp 4.2.0-27.32~14.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2890-2
http://www.ubuntu.com/usn/usn-2890-1
CVE-2013-7446, CVE-2015-7513, CVE-2015-7550, CVE-2015-7990,
CVE-2015-8374, CVE-2015-8543, CVE-2015-8569, CVE-2015-8575,
CVE-2015-8787

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-27.32~14.04.1

[USN-2890-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-2890-1
February 02, 2016

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)

It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)

It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)

Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7990)

It was discovered that the Btrfs implementation in the Linux kernel
incorrectly handled compressed inline extants on truncation. A local
attacker could use this to expose sensitive information. (CVE-2015-8374)

郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2015-8543)

Dmitry Vyukov discovered that the pptp implementation in the Linux kernel
did not verify an address length when setting up a socket. A local attacker
could use this to craft an application that exposed sensitive information
from kernel memory. (CVE-2015-8569)

David Miller discovered that the Bluetooth implementation in the Linux
kernel did not properly validate the socket address length for Synchronous
Connection-Oriented (SCO) sockets. A local attacker could use this to
expose sensitive information. (CVE-2015-8575)

It was discovered that the netfilter Network Address Translation (NAT)
implementation did not ensure that data structures were initialized when
handling IPv4 addresses. An attacker could use this to cause a denial of
service (system crash). (CVE-2015-8787)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
linux-image-4.2.0-27-generic 4.2.0-27.32
linux-image-4.2.0-27-generic-lpae 4.2.0-27.32
linux-image-4.2.0-27-lowlatency 4.2.0-27.32
linux-image-4.2.0-27-powerpc-e500mc 4.2.0-27.32
linux-image-4.2.0-27-powerpc-smp 4.2.0-27.32
linux-image-4.2.0-27-powerpc64-emb 4.2.0-27.32
linux-image-4.2.0-27-powerpc64-smp 4.2.0-27.32

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2890-1
CVE-2013-7446, CVE-2015-7513, CVE-2015-7550, CVE-2015-7990,
CVE-2015-8374, CVE-2015-8543, CVE-2015-8569, CVE-2015-8575,
CVE-2015-8787

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.2.0-27.32