Monday, June 13, 2016

evolution-data-server soname version bump in rawhide the next week

        Hi,
the 3.21.3 release of evolution-data-server changes soname version for
camel, due to some API changes in that sub-library.

I will rebuild packages for which I have commit rights, the same as I
can help with the API change fixes, thus feel free to ping me or drop
an e-mail. I do not think that other than core Evolution packages will
need more attention, others might be simply rebuild.
        Bye,
        Milan
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

[announce] NYC*BUG Wednesday: HardenedBSD

(followup announce coming regarding other upcoming news)

Wednesday, June 15
Adventures in HardenedBSD, Shawn Webb
18:45, Stone Creek Bar & Lounge: 140 E 27th St
Notice: Not the usual first Wednesday

Abstract

This last year has been an amazing one for HardenedBSD.

We're now around 1.5 years old (though our codebase has existed for
longer) and we're starting to get noticed. This presentation talks about
the cool things we're doing in exploit mitigation development and
OPNSense integration.

You'll hear where we've come from, what we're doing now, and where we'll
be headed in the next year. Included will be discussions of ASLR, W^X,
PIE + RELRO, and a few other lower-level tidbits in exploit mitigation
development.

Speaker Bio

Shawn is a security engineer for G2, Inc. He is also the cofounder of
HardenedBSD and one of its lead engineers. He was introduced into the
security industry as a teenager, falling in love with both offensive and
defensive security. Shawn has written tools like libhijack, which aims
to make runtime process infection dead simple on Linux and FreeBSD. Now
he works primarily on the defensive end, implementing exploit mitigation
technologies in HardenedBSD.

_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce

reallost1.fbsd2233449:如何把新产品成功的推向市场?

                    成功的产品经理——产品经理的野蛮成长

【时间地点】 2016年 6月30-7月1日 北京     7月7-8日上海  、7月4-5日深圳 


【参加对象】 企业CEO/总经理、研发总经理/副总、公司总工/技术总监、公司人力资源总监、产品线总监、产品经理/项目经理、PMO(项目管理办公室)成员、市场总监、技术支持总监等


【学习费用】 3200元/人,(含课程讲义、午餐、茶点等)


垂询热线:上海:021-3100 6787、北京:010-5129-9910 ,深圳:0755-6128-0006


QQ、微信·:320588808   ///    值班手机:189-1787-0808    许先生


注:如不需此类信件信息,请发送"删除'至tuiding02@163.com,打扰之处,还请谅解。。。


课程背景:
我们在为国内很多科技企业服务的过程中,发现企业中普遍存在如下问题:
1、产品开发闭门造车,只关注技术,不关注客户,研发从早忙到晚,产品开发的 不少,但赚钱的产品屈指可数产品开发出来才找客户、找卖点,销售人员报怨我们的产品从娘胎中出来就躺在担架上,产品没有优势,也不知道竞争对手产品的弱点,但我们产品的弱点往往被对手抓住。
2、几乎没有产品路标的规划,有规划也主要是技术驱动,客户需求到不了规划人员手中,公司 神经末梢与大脑失去联系。
3、了解市场的不懂技术,懂技术的不了解市场,不知道需求应该谁 负责,缺少完备的需求收集、汇总、分析机制。
4、把销售驱动误以为是市场驱动,销售人员反馈的需求往往是短期行为、而且很个性化,研发 总是被这些短平快的个性化需求驱动的团团转,还被老板骂"你们这帮笨蛋,怎么搞不出几个拳头产品出来?"

当一个企业从单一产品线向多产品线跨越的时候,必须突破的一个瓶颈就是公司产品经理的培养,因为产品经理是公司价值链中最重要的一个环节,是直接面向客户、带领团队创造价值的领军人物,因此产品经理个人及其所率领的团队的能力往往决定了该产品在市场上的竞争力。然而,很多发展中的企业在构建产品管理体系和培养产品经理的过程中却面临很多困惑,比如:
1.产品经理该如何定位?其职责是什么?
2.产品经理需要具备什么样的能力?如何培养?
3.如何与客户有效沟通,从而发掘客户的隐性需求?
4.如何从大量的需求信息中提炼出核心的客户需求?
5.如何策划有竞争力的差异化产品?
6.如何确保策划的核心需求在开发过程中被充分实现?
7.如何把新产品成功的推向市场?
8.如何避免产品经理沦落成"问题经理"?
9.如何实现产品经理从"单挑"模式向"打群架"模式的转变?
10.如何构建适合产品经理成长的优良土壤?
……
基于以上典型问题,我们结合大量的培训 和咨询案例,并不断 总结,从而推出该课程,案例、模板、经验、教训、学员分享等贯穿全课程。


培训收益:
1.了解产品经理产生的背景、时机
2.了解不同时期、不同行业的产品经理定位、职责、素质、能力要求
3.理解产品经理、项目经理、市场经理的关键区别以及相应的组织运作
4.理解产品经理的核心能力是如何折腾出来的
5.掌握如何才能持续策划出有竞争力的产品的方法
6.掌握产品经理如何有效的监管产品开发过程而不需要过度陷入的方法
7.掌握新产品上市管理的方法,确保营销团队顺利接手新产品的销售
8.掌握产品生命周期管理的基本方法和决策机制,把脉产品的退市时机
9.了解业界如何培养产品经理的方法
10.分享讲师50多个咨询项目的产品管理和产品经理队伍建设的案例资料(流程、制度、模板、样例……)


课程大纲:
一、案例分析

二、锦囊之一:搞清研发项目经理的定位、职责与素质模型
1.走上研发项目经理的工作岗位要实现哪些角色转换?
1)从专注于技术变为关注项目
2)自己做好事情到带动整个研发团队
3)从部门内走到部门外,贯穿全流程
4)从关注事情到关注人和事
2.研发项目经理在公司如何定位
1)公司核心价值创造的环节
2)横向角色
3)项目型公司、产品型公司、运营型公司的项目经理的不同定位
3.研发项目经理如何把握项目的本质
1)研发项目管理和运营管理的区别
2)研发项目管理管什么?不管什么?
3)如何从"土匪"变为"正规军"
4)吃透研发项目的四要素
5)平衡研发项目的S、T、Q、C
4.研发项目经理有哪些职责?
5.什么样的人适合做研发项目经理
1)技术能力
2)业务能力
3)项目管理与团队管理的能力
4)人际沟通与处理冲突的能力
5)个人影响力
6.案例分析:某案例公司的研发项目经理的素质模型
7.如何培养研发项目经理
1)建立项目经理的素质模型
2)资源池的培养体系
3)研发项目经理培养积分卡
4)干中学,学中干
8.演练与问题讨论

三、锦囊之二:如何锁定项目的目标
1.研发项目目标的制定
1)研发项目目标制定的标准
2)研发项目目标制定的原则
3)如何完成研发项目目标的制定
2.案例分析:某案例公司研发项目任务书模板
3.研发项目在公司项目中的排序
4.如何根据项目的目标来组建项目团队
5.制定项目目标时如何与公司高层沟通
1)获得高层的认可
2)获得公司的资源
3)汇报机制达成共识
6.演练与问题讨论

四、锦囊之三:如何搞定需求并控制变更
1.产品需求收集(如何从市场角度进行有效的客户需求收集?)
1)研发需求收集流程介绍
2)识别客户?
3)需求收集渠道:外部渠道与内部渠道
4)需求收集需要注意的问题
2.需求收集方法
1)原型法
2)客户访谈法
3)现场观察法
4)其他十种典型的需求收集方法
a.客户决策委员会、用户大会、客户简报
b.高层拜访、标杆学习、Beta测试
c.现场支持、支持热线、行业会议
d.客户满意度调查
e.各个方法的优点、缺点、需求收集的类型介绍
3.需求收集的输出:客户需求收集模板(单项需求收集模板)
4.产品需求整理和分析(如何对客户需求进行整理和分析,形成产品包需求?)
1)研发需求整理和分析流程介绍
2)真正理解客户的意图
3)客户描述和需求陈述
4)客户描述? 需求陈述五原则
a 案例:具体产品客户描述到需求陈述案例分析
5)业界最佳客户需求的八个要素介绍
a 每个要素详细定义
b 每个要素的子要素分解
c 案例:某产品客户需求8要素子要素展开样例介绍
6)如何保证需求的一致性
a 需求冲突矩阵分析法
b 案例:具体需求冲突矩阵分析样例介绍
c 实战演练与问题讨论
5.产品需求的跟踪和验证
1)研发需求持续验证和跟踪流程介绍
2)需求双向跟踪机制(RTM)
a 需求编号规范介绍
b 需求跟踪的必要性
c 前向跟踪
d 后向跟踪
3)需求验证和确认
4)需求验证和跟踪输出(需求双向跟踪模板RTM(关键要素介绍))
6.需求变更控制机制
1)谁负责需求的变更控制
2)如何评估需求变更的影响
3)需求变更的追踪机制
7.演练与问题讨论

五、锦囊之四:研发项目计划制定与控制的能力
1.一个完整的研发项目计划应该考虑的方面
2.研发项目计划包括
1)进度与资源计划
2)质量管理计划
3)风险管理计划
3.进度与资源计划
1)讨论:公司在研发项目计划制定中存在的问题?
2)研发项目计划的作用
3)研发项目计划制定的流程
4)研发项目计划的分级分层管理体系
4.研发项目计划的制定的步骤
1)WBS:最基本的往往是最厉害的(作用、示例)
2)WBS分解的衡量标准
3)PBS、WBS、OBS、RBS之间的对应关系
4)五种常见的估计方法
5)规模、工作量、工期估计
6)PERT图的绘制
7)如何加快项目开发进度
a 关键路径法
b 快速跟踪法
5.质量第一,计划先行
6.谁忽略风险计划,风险就找谁
7.难道沟通也要做计划?
8.十大提高项目执行力的行为
9.借助工具保证执行落地
10.研发项目的分层实施与分层监控
11.研发项目控制的手段:报告+会议
1)项目报告种类
2)项目例会种类
3)变更控制流程
4)业务决策评审
5)研发合同书管理
6)项目审计
7)成本控制
8)QA状态报告
12.演练与问题讨论

六、锦囊之五:研发项目经理绩效管理的能力
1.制定研发项目KPI指标的方法
1)平衡计分卡方法
2)鱼骨图方法
2.考核研发项目的常规KPI指标有哪些?
3.如何把研发项目的目标分解给研发人员
4.研发人员绩效承诺管理
1)对结果的考核
2)对过程的考核
3)对团队意识的考核
5.研发人员制定绩效目标存在的问题分析
1)目标不具挑战性或太具挑战性
2)需求的变更导致项目计划变更,影响绩效目标
3)绩效目标如何量化
6.绩效承诺目标的跟踪与修改
7.研发项目经理如何辅导研发人员的绩效
1)针对不同的员工制定不同的绩效辅导方法
2)绩效辅导的类型
8.研发项目经理如何做好研发人员的绩效评价
1)绩效评价的流程和方法
2)研发项目经理如何与部门经理沟通
9.公司如何从制度上保证项目经理的权威性
10.演练与问题讨论

七、锦囊之六:研发项目经理沟通与处理冲突的能力
1.研发沟通的障碍
1)研发项目管理十大危机之首:缺乏沟通
2)研发沟通的过程、目的和功能
3)研发过程的信息偏差
2.约哈利窗沟通分析
3.沟通的种类
1)正式沟通与非正式沟通
2)书面沟通与口头沟通
3)上行、下行、平行沟通
4)单向与双向沟通
4.研发沟通方式比较
5.如何与上级沟通
1)领导的沟通类型对沟通的影响
2)与领导商谈的难题、要点
3)高层领导喜欢的沟通方式
4)向领导汇报方式和工具
5)汇报会上领导常问的问题
6.如何跨部门沟通
1)不同研发组织架构沟通中要注意的问题
2)跨部门沟通障碍——部门墙
3)等级制度:上司文化
4)平级沟通:自我保护
5)跨部门沟通要点——沟通从心开始
7.项目团队内如何沟通
1)研发人员的沟通特点、缺陷
2)与技术型团队沟通
3)与关系型团队沟通
4)员工沟通需求
5)明确授意——5W2H
8.什么时候冲突具有破坏性
9.什么时候冲突具有建设性
10.研发冲突原因(讨论)
1)目标、有限的资源、方法、事实、价值、角色、风格
11.如何避免冲突(讨论)
12.冲突与研发组织绩效果
13.解决研发冲突的四方面工作
1)组织氛围
2)沟通(GROW方法论)
3)冲突反应风格
a 回避型
b 强硬型
c 迁就型
d 折衷和解型
e 协作型
4)问题解决流程
14.演练与问题讨论

八、总结
1.研发项目经理如何实现角色转换
1)兵熊熊一个,将熊熊一窝
2)怎么才能不是熊将
2.六个锦囊如何融会贯通
1)此时无招胜有招
2)总结、提炼、升华

Fedora 24 Final Go/No-Go Meeting - the 2nd round - on Thursday, June 16th @ 17:00 UTC

Join us on irc.freenode.net in #fedora-meeting-2 for this important
meeting, wherein we shall determine the readiness of the Fedora 24.

The meeting is scheduled at 17:00 UTC. Please follow the [FedoCal]
link to find the time of the meeting in your time-zone.

[FedoCal] https://apps.fedoraproject.org/calendar/meeting/4328/

"Before each public release Development, QA and Release Engineering
meet to determine if the release criteria are met for a particular
release. This meeting is called the Go/No-Go Meeting."

"Verifying that the Release criteria are met is the responsibility of
the QA Team."

For more details about this meeting see:
https://fedoraproject.org/wiki/Go_No_Go_Meeting

In the meantime, keep an eye on the Fedora 24 Final Blocker list:
https://qa.fedoraproject.org/blockerbugs/milestone/24/final/buglist

Thanks for attending,
Jan
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

Friday, June 10, 2016

La Empresa Familiar - En Línea

En línea y en Vivo / Para todo su Equipo con una sola Conexión

La Empresa Familiar: Pros y cómo manejar los Contras
30 de junio - Online en Vivo - 10:00 a 13:00 y de 15:00 a 18:00Hrs

Cuando usted piensa en una empresa familiar, ¿piensa en empresas pequeñas, regionales? ¿O en consorcios internacionales como Walmart, Televisa o Bimbo? Los Walton, los Azcárraga y los Servige son familias reales detrás de corporaciones que ahora cuentan a millones de colaboradores en todo el mundo, y son la prueba de que la empresa que usted y su familia han creado puede llegar tan lejos como lo desee
TEMARIO:

- Características de la empresa familiar


- Los conflictos en la empresa familiar


- Decisiones trascendentes


- Profesionalización de la empresa


- Y mucho más.


¿Requiere la información a la Brevedad?
responda este email con la palabra:
Info - Empresa familiar.
centro telefónico: 018002129393


Lic. Lic. Cinthya Santos
Líder de Proyecto



¿Demasiados mensajes en su cuenta? Responda este mensaje indicando que solo desea recibir CALENDARIO y sólo recibirá un correo al mes. Si desea cancelar la suscripción, solicite su BAJA..

[USN-3008-1] Linux kernel (Qualcomm Snapdragon) vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWmiNAAoJEAUvNnAY1cPYGGcQAL7UYvrxUPN0AvWHRtqppU8L
GO/8w1EXhZWotarUdIPfjrN2eBDBPfvzpkZeJ1ckLFjhqeiXfS3moNBWl+MUZxJx
DyKfdK2xfsjlt9P24wCd2J80e7KZY9FSojUsph27x3Kv6W5pAZ5QDoc8iau1oSzN
xjmycEzAUeflRr4kEumkFf9cB5S7j+dQwm0WjjrZUbdGNhjyr0NbNv9dUl6iT9uO
4tjGOf/+3lOZ168CHPQ/aC53CTqKggcld1oVZA+NpYNpJ3y/kwXazBagqjs7U150
TxqVuLNsX9zs9gzAXQQ0u+Z5eDQj8QualVFZNEISAOUaIYWIasHsSqKyjqYkcyaH
yW1Y6Afhj9YpUVXfyYlIjmQWI6BycqJyOmeJJ8NALmqiYecPV2rpMj12PhrRL55S
xgj94C6gHN8VjvqNVQwX55PNvCPA2wU3dGXZPJXk6mgU6mMLU7bAvSIdpnKq9KzJ
SsaXLW8t6oeG+QdTw75XMpYVZI+DLCW7gVnFGGqrhhqkasyLaW775Ro40KYzxLlD
+MPX4VCvv3s3YVn6w+ZMKXBrMyG14Wr/gj1YzK4gePs9vpNXCFFJ6bkUwU4v3jP7
gVlzUa4Iz39L4v06/gmJnmU3MiVI2McN2Ha18488aRbzTsyP7AZHnm9ECrKTm1YR
7cvS9t2jH0NoN/w3siv8
=otB0
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3008-1
June 10, 2016

linux-snapdragon vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

The system could be made to crash under certain conditions.

Software Description:
- linux-snapdragon: Linux kernel for Snapdragon Processors

Details:

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.4.0-1015-snapdragon 4.4.0-1015.18

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3008-1
CVE-2016-1583

Package Information:
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1015.18

[USN-3005-1] Linux kernel (Xenial HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWmhBAAoJEAUvNnAY1cPYfR8P/20PLZaO5P78MiYSI69RQnK1
B/NZn6/7FGkltShLnhv7RZEdWyHSHcUwg8SVD+K5q9OMuiG6QOs0HVLoPk58JkVM
yFO3M5cpSOZ5nqPi5nmV33m/M9Ny6JzdzzbVMzShSebBKN8C91q1xOgghphhRjZL
C3PPoRyFZW2r6EnDVFQnyQqY8F94H7Ikkz1HZZVd2KPawXLVia48jAwOiJP07szY
/rbdFu97LumNaZwx0h8LLKeQPCAj7/rtqNE6o481MGXy0dE1xihXRTc5fY2UZrqC
1m8vKktpBeXvJd2/bhsIYiKNg6wdSkoPqBup72n7YlDax0S6aLC+q+p4TfPZ6GOg
qggc/01k8yV+fWIIvEO62B6XuGYNxl6MAKKGIM1csOKU78vo4hi2GvELel4P2NsM
YQaUnDms/9trUwfv+WztZmD+vp30T9Ftx5QveRth6WGoML1iyQkKq4DbYlJjIO77
cUmc7DuEqXZ5kB+rK10EuyQ5lKZ2cwSG66+3X0+4IcYVTkH5kmWIpAIc029RMvYL
con8l6RxsoeQnu9kabHsj+eacSl3go26KYVDphfSkYI9AOGsPghvruQ00TogwhTs
080wTpB9IfOU1fLWgX/Z/T/lqmRpPXoy/oLyKnIzhizppX5cQjJVqJtT/w+7Qd1W
Raq0fbOcNNIdjQPNXR7V
=xLOz
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3005-1
June 10, 2016

linux-lts-xenial vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Multiple race conditions where discovered in the Linux kernel's ext4 file
system. A local user could exploit this flaw to cause a denial of service
(disk corruption) by writing to a page that is associated with a different
users file after unsynchronized hole punching and page-fault handling.
(CVE-2015-8839)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Jann Horn discovered that the extended Berkeley Packet Filter (eBPF)
implementation in the Linux kernel could overflow reference counters on
systems with more than 32GB of physical ram and with RLIMIT_MEMLOCK set to
infinite. A local unprivileged attacker could use to create a use-after-
free situation, causing a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-4558)

Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privileges on
systems where InifiniBand related kernel modules are loaded.
(CVE-2016-4565)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-4.4.0-24-generic 4.4.0-24.43~14.04.1
linux-image-4.4.0-24-generic-lpae 4.4.0-24.43~14.04.1
linux-image-4.4.0-24-lowlatency 4.4.0-24.43~14.04.1
linux-image-4.4.0-24-powerpc-e500mc 4.4.0-24.43~14.04.1
linux-image-4.4.0-24-powerpc-smp 4.4.0-24.43~14.04.1
linux-image-4.4.0-24-powerpc64-emb 4.4.0-24.43~14.04.1
linux-image-4.4.0-24-powerpc64-smp 4.4.0-24.43~14.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3005-1
CVE-2015-8839, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3961, CVE-2016-4485, CVE-2016-4486, CVE-2016-4558,
CVE-2016-4565, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-24.43~14.04.1

[USN-3006-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWmhiAAoJEAUvNnAY1cPYfZ4P/RPnMKKD5FFWXMfQ/2D0xJbV
y1FIuCg6zXcz9z3CYhFaGHa5Nkhc5kZ+NiBN7Ee9NGrULUjHX4T4xaF/tJUeMBjz
l2QAYOPxIbGPApUNO/OVudxDqY8SZzeubIVXqZpxnHSGEchUj3vdb26chdO2NON7
P1NE2P3EjSaIe8kP6olC5xSg7HlojNjLkZ+THsgAq9PPqpZ11rpcomEI+JHHjT1V
v8Ztfh0gTGRE/ZoGlhAtWYt5FXzfRKJ37BhEjpdTdnE3mlAdazrjPOxJ8qPGidqK
6CJ+D4MkDSQHwXg+AF+z/tGXgR9RUOnIL6LwXqn8BkqIw+gcl7mG46994W5BlLYz
DGZvh73hmgywC8wbT8GAs+Df4B0bC7Uc/VQaZkmPeggLIJpZ0MCuUqHuLrxf8GSq
rjNlsCArxQIsnrjSruG/SrB6oCaYVG3apAIo5UXFEVXOeAr/I50+RUBB9uA+WOrl
/WeWWs3xmZ6H7yEOw2Jh3sHtVakiFqpPgSQCYYefH1gWEywpK5S1jhk6wVW1BIwC
T2Q6MaCb9OQRTv4o/La1P0KX1lUxgPhpkaw6/5Ti6L0ptwcSLvwNZQjGkjkplCjD
t/x8LQ5d8MAKpLnbE54K4th9H4mOoJhIn0wwEwZcvitAtouiq3nmeUO7RtWdVcZl
2KFjP6HvOB+lTL1GCEyO
=lcVp
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3006-1
June 10, 2016

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Multiple race conditions where discovered in the Linux kernel's ext4 file
system. A local user could exploit this flaw to cause a denial of service
(disk corruption) by writing to a page that is associated with a different
users file after unsynchronized hole punching and page-fault handling.
(CVE-2015-8839)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Jann Horn discovered that the extended Berkeley Packet Filter (eBPF)
implementation in the Linux kernel could overflow reference counters on
systems with more than 32GB of physical ram and with RLIMIT_MEMLOCK set to
infinite. A local unprivileged attacker could use to create a use-after-
free situation, causing a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-4558)

Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privileges on
systems where InifiniBand related kernel modules are loaded.
(CVE-2016-4565)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.4.0-24-generic 4.4.0-24.43
linux-image-4.4.0-24-generic-lpae 4.4.0-24.43
linux-image-4.4.0-24-lowlatency 4.4.0-24.43
linux-image-4.4.0-24-powerpc-e500mc 4.4.0-24.43
linux-image-4.4.0-24-powerpc-smp 4.4.0-24.43
linux-image-4.4.0-24-powerpc64-emb 4.4.0-24.43
linux-image-4.4.0-24-powerpc64-smp 4.4.0-24.43

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3006-1
CVE-2015-8839, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3961, CVE-2016-4485, CVE-2016-4486, CVE-2016-4558,
CVE-2016-4565, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.4.0-24.43

[USN-3007-1] Linux kernel (Raspberry Pi 2) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWmh5AAoJEAUvNnAY1cPYgykQALz0i6v2njH+TNfBZVSuCw3o
gziellIDeuSGvuAo0P7TESWm8C5ZV9bShgKzLTAYSNu7aToLy2dxUIAvqBFL1WQi
K48kFJW8ygODQoE8RdHeTYdiOG+4DZtrwCnMnYlJp4VqqkNhq5fO9a3K7lnCzVd5
bEBVeQKnSAfFARnJP3nmw6S2iAzflnF29mlrZXXVRIQdMrs0iHzxTFhLdOgaVSTS
jYIPB1CbfYPE5Yi+J6/ZUGtEk0JbP21XLbThR4LFoNHnrqAeLLr/7SSg0km+4b2K
d2cTq8sSj370J50xo9aAbCh6WwtxGz9ctIOs9t7AiNoc+UEKQ0PrN5v9uFV+6z18
1N9N2XhUvl4bMOmHkybaByYt8PqP0n0YmR+Lv+fhXOkZG+tNPgGbTZJa5uIqcImE
7qu5gJlrQ8DSGAFjwZnRaZXegFjBj6dqq/bdhX1t4+DUDTFNY2CTCDdxNG4x1nhZ
jvaXi9pRKsXD8tOt6kjv9iEImL6haAMwgnQR7Uf/eOqenA8gboit/gsXIDjohjat
HJ/I5Egw3gPp5LHrTSGFARQDvhOZmemqVE/qO3oT2ssnBuu+Pec6V7XTe4pLGiSG
7qsPbBy69obqq39MhGY1nfb2EMjB2TA4+7AW7/79xBZx4fEBNW11iWa+0mrIeWpc
EBXMyf/yNm4yVXqdLGh1
=X0tG
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3007-1
June 10, 2016

linux-raspi2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-raspi2: Linux kernel for Raspberry Pi 2

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Multiple race conditions where discovered in the Linux kernel's ext4 file
system. A local user could exploit this flaw to cause a denial of service
(disk corruption) by writing to a page that is associated with a different
users file after unsynchronized hole punching and page-fault handling.
(CVE-2015-8839)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Jann Horn discovered that the extended Berkeley Packet Filter (eBPF)
implementation in the Linux kernel could overflow reference counters on
systems with more than 32GB of physical ram and with RLIMIT_MEMLOCK set to
infinite. A local unprivileged attacker could use to create a use-after-
free situation, causing a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-4558)

Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privileges on
systems where InifiniBand related kernel modules are loaded.
(CVE-2016-4565)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.4.0-1012-raspi2 4.4.0-1012.16

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3007-1
CVE-2015-8839, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3961, CVE-2016-4485, CVE-2016-4486, CVE-2016-4558,
CVE-2016-4565, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1012.16

[USN-3004-1] Linux kernel (Raspberry Pi 2) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWldgAAoJEAUvNnAY1cPYKZwP/1u/W4gO6X/Pfd4gVVAJxeWg
zejK7b/w8JIV+FqznGwlGI5gGTfH9p4RGM/Efn4pWYVZfvJWS9Wk5mOHoaBCqKSC
K8zKSJ6oyWkwi9P0nTD+naMrLbhJtWl9o0D0oQFQ3PEoD0Lys4kf+TQY2bEHmBen
N7r6a082vyhtWpok55wz04AnrRxSKNroczY2KoLdDyodvs6Qbm6azvoTEdGUliUb
oroGYas/Sp8tKbMKICGNESrWEDUFdV+ULja4QG+LbDHuNijV5haypB7p+aaHjDMq
xdjOKr/IGKKtOuMHRnmhsg9bLljVKnUC3IkNOXf5yf8vF4erqVD9a8+BEnM9uMTU
BQMMY2/3xpjjJv71CuVoVZiiAdvIAFpiTXUQIeB4DYddixWAhwGCCJAoFx/08dFI
C/QkSUELRWdw+U30615kYY3QwNwkpWwdD1IKKlaYEILZ2Ter3YEAG1H9LPzKDBYE
fEo5nL91+QKwvxQrdF6sDtJpU+5xaZCRhG/OcL8SvITN2pfrc6YXBFKHCw/HWKGl
I6aIIRNwK1Xmj24uaLcIFznIyp1WFFmIwXCzMn5irVa0nD9j38F+74J7OJKGUvKs
fL6Gr19+uW0QxfHj/HK+L0iM55vHuN8TRzWY4bxxdD0upxKilhaRrKaUA3/TcWiB
dfietOVg46SEYRvyU2yx
=VjrD
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3004-1
June 10, 2016

linux-raspi2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-raspi2: Linux kernel for Raspberry Pi 2

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB
over wifi device drivers in the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash) or obtain potentially
sensitive information from kernel memory. (CVE-2015-4004)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privileges on
systems where InifiniBand related kernel modules are loaded.
(CVE-2016-4565)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
linux-image-4.2.0-1031-raspi2 4.2.0-1031.41

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3004-1
CVE-2015-4004, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3672, CVE-2016-3951, CVE-2016-3955, CVE-2016-3961,
CVE-2016-4485, CVE-2016-4486, CVE-2016-4565, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux-raspi2/4.2.0-1031.41

[USN-3003-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWldGAAoJEAUvNnAY1cPY46wP/15zcFaHbVvWQ1URnzqVYccC
4nQA98Abh0aomIa8XKYHyuoe4A2Jpdd7Q2f0J3qdPboHzjBxILfeD9yVTEjb0om8
Hp7CNgs547ha5qSzlGdh4Pg8jQcjn1N2xp/er/qGl4wCAaLegKfsBOQHwZ+m4/Bx
OyXxR4oKMQ3pYWgWVAHQiCqEVboWd3oX5w1Jqw/ZdpVIFiNh+2GV2t9wMvYzLnXP
gFO3ts95ocdCpaE+Xh7eH9fII4y7iM4oduIU43ItGcLMvTlBV+SouR3SZKLNcCH0
q3gmUhMKPZw/4sehhrXw75a79DspYeh2oUZkrGyahqyEjzHrm+ZebIvu8i33l7QI
z+oke0tA5YFtB7K3dsC3bZFYHb4+Vr6Z9A29XkB6JZHgO7OLIn1iO4PgJem4UuQq
byhoFWwy2OPMUNwdIh4IwIZ9gZ4JSi3kuxYev0NjsTdklGYzCii8K59N51ZkPFQn
qo5/7FboaUkElW1FORo2jzXdemvY1/JkfTo05W29S3Ab5QRH58OHhqU7VXy1OBrO
xCGyq1nTYeUmi4NVN+RMwcrrSEB0UG88vG0WpnlKrywn2HmfNFOYtOW+T/XirjNp
1G4nRfOGVAe2SW2ZcKRHC+2jsIaDHUSpAjPt5/dx5xHVL8WfSWcUi7MnL0/yyFV2
SAbsq9DYH7E1aVs35Jik
=Bx4t
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3003-1
June 10, 2016

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB
over wifi device drivers in the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash) or obtain potentially
sensitive information from kernel memory. (CVE-2015-4004)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privileges on
systems where InifiniBand related kernel modules are loaded.
(CVE-2016-4565)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
linux-image-4.2.0-38-generic 4.2.0-38.45
linux-image-4.2.0-38-generic-lpae 4.2.0-38.45
linux-image-4.2.0-38-lowlatency 4.2.0-38.45
linux-image-4.2.0-38-powerpc-e500mc 4.2.0-38.45
linux-image-4.2.0-38-powerpc-smp 4.2.0-38.45
linux-image-4.2.0-38-powerpc64-emb 4.2.0-38.45
linux-image-4.2.0-38-powerpc64-smp 4.2.0-38.45

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3003-1
CVE-2015-4004, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3672, CVE-2016-3951, CVE-2016-3955, CVE-2016-3961,
CVE-2016-4485, CVE-2016-4486, CVE-2016-4565, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.2.0-38.45

[USN-3002-1] Linux kernel (Wily HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXWlczAAoJEAUvNnAY1cPYNbUQAJIy0DhHz2omkRzBCbUZxFCr
GDR+0dE0syHjYPWJIO28vyo/5wDiUmeDVpYRukQwetlMNJ81SSYxOA+LPs4xSppX
9DZ1PO1r0hmJQagQe0n9SjRaV6QfmMzfVncMTW5Oko6GHtlTqMBLgs+Z5/P3I/8T
SUxdvxYbTap/XWyr6VcXsUgHLiDXP6X+9F90q5Ol6QUXQa9JiOvVnSjG+UOZvHFl
9hdAQY0BFt+K5AXREwI8pG/6sXSwb6ymMiLWL/QhhqfUQd4OK1LJhGx8NLqOhTZO
ILkUppnOtCvUz6OvzFaTbeQKtNSf09VK5+Tv+snhIatjgc0LsEkO4fQpTgPS7JVs
7x8Y2ARq/CQztEJ3O4j4JMbq76FcBb1OZ8K8LPMQ6Vi+TMuBi9UY866ZMvoF14E+
Ncik693ABlVHwAeqznI3aji50uC3yO1BgDZii3eR6nKDzV2N4a1hkIBGFPMR47gG
VKEC9GKmQpGMZyD4TH5GMPAbWdDsoP+73w8RrnNm1Hn6O4Epn07W29AD/iZXqFjc
T59hQaUQo2VXm4SiyZWmapFRrz7uBzATivddLhBmeqEw7f3P355o1mJbmnFCvKFT
Pro+R26rqkWofUlJkNZdd7bIJO/0n/MC6velBTiUT/UY3lTvncWMMfqlJiTmViDI
yKK9NjFoe0fWRl5+FWvJ
=ZGNH
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3002-1
June 10, 2016

linux-lts-wily vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-wily: Linux hardware enablement kernel from Wily for Trusty

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jann Horn discovered that eCryptfs improperly attempted to use the mmap()
handler of a lower filesystem that did not implement one, causing a
recursive page fault to occur. A local unprivileged attacker could use to
cause a denial of service (system crash) or possibly execute arbitrary code
with administrative privileges. (CVE-2016-1583)

Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB
over wifi device drivers in the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash) or obtain potentially
sensitive information from kernel memory. (CVE-2015-4004)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Vitaly Kuznetsov discovered that the Linux kernel did not properly suppress
hugetlbfs support in X86 paravirtualized guests. An attacker in the guest
OS could cause a denial of service (guest system crash). (CVE-2016-3961)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

Jann Horn discovered that the InfiniBand interfaces within the Linux kernel
could be coerced into overwriting kernel memory. A local unprivileged
attacker could use this to possibly gain administrative privileges on
systems where InifiniBand related kernel modules are loaded.
(CVE-2016-4565)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-4.2.0-38-generic 4.2.0-38.45~14.04.1
linux-image-4.2.0-38-generic-lpae 4.2.0-38.45~14.04.1
linux-image-4.2.0-38-lowlatency 4.2.0-38.45~14.04.1
linux-image-4.2.0-38-powerpc-e500mc 4.2.0-38.45~14.04.1
linux-image-4.2.0-38-powerpc-smp 4.2.0-38.45~14.04.1
linux-image-4.2.0-38-powerpc64-emb 4.2.0-38.45~14.04.1
linux-image-4.2.0-38-powerpc64-smp 4.2.0-38.45~14.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-3002-1
CVE-2015-4004, CVE-2016-1583, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3672, CVE-2016-3951, CVE-2016-3955, CVE-2016-3961,
CVE-2016-4485, CVE-2016-4486, CVE-2016-4565, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-38.45~14.04.1