CentOS Errata and Security Advisory 2017:0293 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0293.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
8e5db1418cf0c4cc98c3b3f75c73ae681e6d1af6e6af960bc03f96dd38c444c6 kernel-2.6.32-642.13.2.el6.i686.rpm
7b7c0130f6d949dbab08c622d33d3a965189992d9f790d2422ab847f7524266a kernel-abi-whitelists-2.6.32-642.13.2.el6.noarch.rpm
d34bf5af966a9598fa12736e7cae72c3a02da76332774123b0e16905f88d4e95 kernel-debug-2.6.32-642.13.2.el6.i686.rpm
bcef4faf1884b67f02e7b5a046bfc28ddb9f3c2f5009e86afefe00123a8d74e8 kernel-debug-devel-2.6.32-642.13.2.el6.i686.rpm
2b2ca285b26e3b90eee5ac182fcb8588532fb882632304f8a21c3e78dbb9c4a2 kernel-devel-2.6.32-642.13.2.el6.i686.rpm
83bc6d344aff521bc6b5766347fec8f2ccb482330be746661624d5e76624616a kernel-doc-2.6.32-642.13.2.el6.noarch.rpm
ca77321a113b1a089c61a9d053efc06063476a0a6aeb08c257a3fb58591e8feb kernel-firmware-2.6.32-642.13.2.el6.noarch.rpm
60fb671174abdfa8ed467ff6cd71cf8ecae26f06ed94e6cd8aaca6b3820f29d5 kernel-headers-2.6.32-642.13.2.el6.i686.rpm
e1ddc8fce78af40b1202267e7bdbefbb01f7b8ad9a75d68e0e88587dc68b7d4c perf-2.6.32-642.13.2.el6.i686.rpm
70bbabecf85895e3d7a1fb2d3cc6ffeccdcf0bc664bd3d994670a05cf7c6e7f7 python-perf-2.6.32-642.13.2.el6.i686.rpm
x86_64:
d42ff04a27c00197952bb3b84c66891022fadff49b2a907039061189e648820c kernel-2.6.32-642.13.2.el6.x86_64.rpm
7b7c0130f6d949dbab08c622d33d3a965189992d9f790d2422ab847f7524266a kernel-abi-whitelists-2.6.32-642.13.2.el6.noarch.rpm
eebf181ae2c9217b4a65831903298e74454c11788ff3c4b66d66796f0d539736 kernel-debug-2.6.32-642.13.2.el6.x86_64.rpm
bcef4faf1884b67f02e7b5a046bfc28ddb9f3c2f5009e86afefe00123a8d74e8 kernel-debug-devel-2.6.32-642.13.2.el6.i686.rpm
6224f08bbc8ec073385e4d9c6a4d18d1689e9914b44710214660d37a1725e4bf kernel-debug-devel-2.6.32-642.13.2.el6.x86_64.rpm
af93fee2aa92ca20fc2b2a88415b9abeb1a4d8bb348f694216d7a3eaf07f7d61 kernel-devel-2.6.32-642.13.2.el6.x86_64.rpm
83bc6d344aff521bc6b5766347fec8f2ccb482330be746661624d5e76624616a kernel-doc-2.6.32-642.13.2.el6.noarch.rpm
ca77321a113b1a089c61a9d053efc06063476a0a6aeb08c257a3fb58591e8feb kernel-firmware-2.6.32-642.13.2.el6.noarch.rpm
49e71d4eb8403a790910ad73529e72a52971ba0aebbe07dac25172946e94f200 kernel-headers-2.6.32-642.13.2.el6.x86_64.rpm
5b0d68de2c859691712276038c2640da96aeec17754b0aa5d0ffbd0fc2013261 perf-2.6.32-642.13.2.el6.x86_64.rpm
0455e0f63e3966926a1bbf0bd7882b90a67db437ad2e63b38800d8b6aa94c4be python-perf-2.6.32-642.13.2.el6.x86_64.rpm
Source:
888ead19200985f6ad2a8f8fd53336e57b695ceb0ae47c026f82a28f67f70e7c kernel-2.6.32-642.13.2.el6.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
Wednesday, February 22, 2017
[USN-3142-2] ImageMagick regression
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCgAGBQJYrfOZAAoJEGVp2FWnRL6TT7YQAI8OLewYNNONcsD0r49Wnq+m
ezWrVMnUJBg8pdv6NRYJDH5V6SFPaUEMkEt18aTiHPfSLC8MTQPiKxZrEcXPb2ly
G+zjMCL2aJzk7ZGFpM5YEXntp+JU0eUvOL3DteTab498OlnayZuNtNqnAIHZoKoN
SXqpeDnp+XbQLgfEPhysOGXRzXR2JquTylwejp72CIkKPGEFOc7NHtOB3GXWqNQj
6MsCXSLiEDc45DvvzotZMpFj0avFTXSibJmxzyEt3ctx4WwqojxnuopR3jTteAmM
ksSrHr/TPSL2x5mdSjt6m3OHLZ99/RUYpjEtfc6JWxOEejWqFi9b7JXGshXhxj5H
pC1QLIRMz6mQ4eEHGLCir4C13qWNR/rFp/MuYxqq0qvjYak7whD7Ff4Yq6B5j1kH
IJcWrwLmE22b0sB28BM8Yf0HdSAzu3tIQ45eKjmfuTILdOjpb157VohBFTgJNU07
364cPVAa5LFAPsmhrx5LDSY8JSC7AY32MqxrO8SgNd672U+i7v6bKkbDefhieAaw
azRYi56IZZqT7cIHnB10cwZixeF7eyhvU6ngxuIV9bxDZ0bPum3Kq+WmBRP2xkrn
3NN9M07v0KC2BxmKVp/2i0Kq467bh/LF2c8e5g7REXJj7vgAg1XfGsupxJWTfvkB
jmdmu0Wzbm9BLf3oYDrT
=2oqf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3142-2
February 22, 2017
imagemagick regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
USN-3142-1 introduced a regression in ImageMagick.
Software Description:
- imagemagick: Image manipulation programs and library
Details:
USN-3142-1 fixed vulnerabilities in ImageMagick. The security fixes
introduced a regression with text labels and a regression with the text
coder. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.10:
imagemagick 8:6.8.9.9-7ubuntu8.3
imagemagick-6.q16 8:6.8.9.9-7ubuntu8.3
libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu8.3
libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu8.3
libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu8.3
Ubuntu 16.04 LTS:
imagemagick 8:6.8.9.9-7ubuntu5.4
imagemagick-6.q16 8:6.8.9.9-7ubuntu5.4
libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.4
libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.4
libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu5.4
Ubuntu 14.04 LTS:
imagemagick 8:6.7.7.10-6ubuntu3.4
libmagick++5 8:6.7.7.10-6ubuntu3.4
libmagickcore5 8:6.7.7.10-6ubuntu3.4
libmagickcore5-extra 8:6.7.7.10-6ubuntu3.4
Ubuntu 12.04 LTS:
imagemagick 8:6.6.9.7-5ubuntu3.7
libmagick++4 8:6.6.9.7-5ubuntu3.7
libmagickcore4 8:6.6.9.7-5ubuntu3.7
libmagickcore4-extra 8:6.6.9.7-5ubuntu3.7
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-3142-2
http://www.ubuntu.com/usn/usn-3142-1
https://launchpad.net/bugs/1589580, https://launchpad.net/bugs/1646485
Package Information:
https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.3
https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.4
https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.4
https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.7
Version: GnuPG v2
iQIcBAEBCgAGBQJYrfOZAAoJEGVp2FWnRL6TT7YQAI8OLewYNNONcsD0r49Wnq+m
ezWrVMnUJBg8pdv6NRYJDH5V6SFPaUEMkEt18aTiHPfSLC8MTQPiKxZrEcXPb2ly
G+zjMCL2aJzk7ZGFpM5YEXntp+JU0eUvOL3DteTab498OlnayZuNtNqnAIHZoKoN
SXqpeDnp+XbQLgfEPhysOGXRzXR2JquTylwejp72CIkKPGEFOc7NHtOB3GXWqNQj
6MsCXSLiEDc45DvvzotZMpFj0avFTXSibJmxzyEt3ctx4WwqojxnuopR3jTteAmM
ksSrHr/TPSL2x5mdSjt6m3OHLZ99/RUYpjEtfc6JWxOEejWqFi9b7JXGshXhxj5H
pC1QLIRMz6mQ4eEHGLCir4C13qWNR/rFp/MuYxqq0qvjYak7whD7Ff4Yq6B5j1kH
IJcWrwLmE22b0sB28BM8Yf0HdSAzu3tIQ45eKjmfuTILdOjpb157VohBFTgJNU07
364cPVAa5LFAPsmhrx5LDSY8JSC7AY32MqxrO8SgNd672U+i7v6bKkbDefhieAaw
azRYi56IZZqT7cIHnB10cwZixeF7eyhvU6ngxuIV9bxDZ0bPum3Kq+WmBRP2xkrn
3NN9M07v0KC2BxmKVp/2i0Kq467bh/LF2c8e5g7REXJj7vgAg1XfGsupxJWTfvkB
jmdmu0Wzbm9BLf3oYDrT
=2oqf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3142-2
February 22, 2017
imagemagick regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
USN-3142-1 introduced a regression in ImageMagick.
Software Description:
- imagemagick: Image manipulation programs and library
Details:
USN-3142-1 fixed vulnerabilities in ImageMagick. The security fixes
introduced a regression with text labels and a regression with the text
coder. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.10:
imagemagick 8:6.8.9.9-7ubuntu8.3
imagemagick-6.q16 8:6.8.9.9-7ubuntu8.3
libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu8.3
libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu8.3
libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu8.3
Ubuntu 16.04 LTS:
imagemagick 8:6.8.9.9-7ubuntu5.4
imagemagick-6.q16 8:6.8.9.9-7ubuntu5.4
libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.4
libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.4
libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu5.4
Ubuntu 14.04 LTS:
imagemagick 8:6.7.7.10-6ubuntu3.4
libmagick++5 8:6.7.7.10-6ubuntu3.4
libmagickcore5 8:6.7.7.10-6ubuntu3.4
libmagickcore5-extra 8:6.7.7.10-6ubuntu3.4
Ubuntu 12.04 LTS:
imagemagick 8:6.6.9.7-5ubuntu3.7
libmagick++4 8:6.6.9.7-5ubuntu3.7
libmagickcore4 8:6.6.9.7-5ubuntu3.7
libmagickcore4-extra 8:6.6.9.7-5ubuntu3.7
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-3142-2
http://www.ubuntu.com/usn/usn-3142-1
https://launchpad.net/bugs/1589580, https://launchpad.net/bugs/1646485
Package Information:
https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.3
https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.4
https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.4
https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.7
[CentOS-announce] CESA-2017:0190 Critical CentOS 7 firefox Security Update
CentOS Errata and Security Advisory 2017:0190 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0190.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
38bdd177d609902c6d514deae731df1f6778409730fa61dd213ad0937d54223c firefox-45.7.0-2.el7.centos.i686.rpm
4ce5659c46dee0b5a25d4e6583e9d498b2d146a9ba33565d1c35a2b983766942 firefox-45.7.0-2.el7.centos.x86_64.rpm
Source:
7db60cb74cd564e32e8e9341c8b1c80e032afa31acfe7c155d0a725a2c80126b firefox-45.7.0-2.el7.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0190.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
38bdd177d609902c6d514deae731df1f6778409730fa61dd213ad0937d54223c firefox-45.7.0-2.el7.centos.i686.rpm
4ce5659c46dee0b5a25d4e6583e9d498b2d146a9ba33565d1c35a2b983766942 firefox-45.7.0-2.el7.centos.x86_64.rpm
Source:
7db60cb74cd564e32e8e9341c8b1c80e032afa31acfe7c155d0a725a2c80126b firefox-45.7.0-2.el7.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2017:0190 Critical CentOS 6 firefox Security Update
CentOS Errata and Security Advisory 2017:0190 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0190.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f34f42fb0d7c2d68da3493786c3ea6db8a5c3025ec23c4920f33739466aee8c5 firefox-45.7.0-2.el6.centos.i686.rpm
x86_64:
f34f42fb0d7c2d68da3493786c3ea6db8a5c3025ec23c4920f33739466aee8c5 firefox-45.7.0-2.el6.centos.i686.rpm
b905dbe1aeb129fcf9dfcdae0476003f4d6f5e73615762346badf37e76c3a43d firefox-45.7.0-2.el6.centos.x86_64.rpm
Source:
98283468cf9d1e539fc7dfbe25e79160d9b9c631dd30d1fd4cef84d1fd64b573 firefox-45.7.0-2.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0190.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f34f42fb0d7c2d68da3493786c3ea6db8a5c3025ec23c4920f33739466aee8c5 firefox-45.7.0-2.el6.centos.i686.rpm
x86_64:
f34f42fb0d7c2d68da3493786c3ea6db8a5c3025ec23c4920f33739466aee8c5 firefox-45.7.0-2.el6.centos.i686.rpm
b905dbe1aeb129fcf9dfcdae0476003f4d6f5e73615762346badf37e76c3a43d firefox-45.7.0-2.el6.centos.x86_64.rpm
Source:
98283468cf9d1e539fc7dfbe25e79160d9b9c631dd30d1fd4cef84d1fd64b573 firefox-45.7.0-2.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2017:0190 Critical CentOS 5 firefox Security Update
CentOS Errata and Security Advisory 2017:0190 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0190.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
4f351259abd6614da05b1ea8e9e4b83486631cadb9aa439996c7070f9eff8588 firefox-45.7.0-2.el5.centos.i386.rpm
x86_64:
4f351259abd6614da05b1ea8e9e4b83486631cadb9aa439996c7070f9eff8588 firefox-45.7.0-2.el5.centos.i386.rpm
1e2b1680b6c395039fafb267db3426fde8c4f2c06b2ba9744f11e18736d2917f firefox-45.7.0-2.el5.centos.x86_64.rpm
Source:
fb33febf301919266593261c3e79a43af3957012b04083b99dc89b5053990019 firefox-45.7.0-2.el5.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0190.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
4f351259abd6614da05b1ea8e9e4b83486631cadb9aa439996c7070f9eff8588 firefox-45.7.0-2.el5.centos.i386.rpm
x86_64:
4f351259abd6614da05b1ea8e9e4b83486631cadb9aa439996c7070f9eff8588 firefox-45.7.0-2.el5.centos.i386.rpm
1e2b1680b6c395039fafb267db3426fde8c4f2c06b2ba9744f11e18736d2917f firefox-45.7.0-2.el5.centos.x86_64.rpm
Source:
fb33febf301919266593261c3e79a43af3957012b04083b99dc89b5053990019 firefox-45.7.0-2.el5.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[USN-3209-1] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-3209-1
February 22, 2017
linux, linux-raspi2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.10
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
- linux-raspi2: Linux kernel for Raspberry Pi 2
Details:
It was discovered that the generic SCSI block layer in the Linux kernel did
not properly restrict write operations in certain situations. A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2016-10088)
Jim Mattson discovered that the KVM implementation in the Linux kernel
mismanages the #BP and #OF exceptions. A local attacker in a guest virtual
machine could use this to cause a denial of service (guest OS crash).
(CVE-2016-9588)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.10:
linux-image-4.8.0-1026-raspi2 4.8.0-1026.29
linux-image-4.8.0-39-generic 4.8.0-39.42
linux-image-4.8.0-39-generic-lpae 4.8.0-39.42
linux-image-4.8.0-39-lowlatency 4.8.0-39.42
linux-image-4.8.0-39-powerpc-e500mc 4.8.0-39.42
linux-image-4.8.0-39-powerpc-smp 4.8.0-39.42
linux-image-4.8.0-39-powerpc64-emb 4.8.0-39.42
linux-image-generic 4.8.0.39.50
linux-image-generic-lpae 4.8.0.39.50
linux-image-lowlatency 4.8.0.39.50
linux-image-powerpc-e500mc 4.8.0.39.50
linux-image-powerpc-smp 4.8.0.39.50
linux-image-powerpc64-emb 4.8.0.39.50
linux-image-raspi2 4.8.0.1026.29
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3209-1
CVE-2016-10088, CVE-2016-9588, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/4.8.0-39.42
https://launchpad.net/ubuntu/+source/linux-raspi2/4.8.0-1026.29
Ubuntu Security Notice USN-3209-1
February 22, 2017
linux, linux-raspi2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.10
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
- linux-raspi2: Linux kernel for Raspberry Pi 2
Details:
It was discovered that the generic SCSI block layer in the Linux kernel did
not properly restrict write operations in certain situations. A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2016-10088)
Jim Mattson discovered that the KVM implementation in the Linux kernel
mismanages the #BP and #OF exceptions. A local attacker in a guest virtual
machine could use this to cause a denial of service (guest OS crash).
(CVE-2016-9588)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.10:
linux-image-4.8.0-1026-raspi2 4.8.0-1026.29
linux-image-4.8.0-39-generic 4.8.0-39.42
linux-image-4.8.0-39-generic-lpae 4.8.0-39.42
linux-image-4.8.0-39-lowlatency 4.8.0-39.42
linux-image-4.8.0-39-powerpc-e500mc 4.8.0-39.42
linux-image-4.8.0-39-powerpc-smp 4.8.0-39.42
linux-image-4.8.0-39-powerpc64-emb 4.8.0-39.42
linux-image-generic 4.8.0.39.50
linux-image-generic-lpae 4.8.0.39.50
linux-image-lowlatency 4.8.0.39.50
linux-image-powerpc-e500mc 4.8.0.39.50
linux-image-powerpc-smp 4.8.0.39.50
linux-image-powerpc64-emb 4.8.0.39.50
linux-image-raspi2 4.8.0.1026.29
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3209-1
CVE-2016-10088, CVE-2016-9588, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/4.8.0-39.42
https://launchpad.net/ubuntu/+source/linux-raspi2/4.8.0-1026.29
[USN-3206-1] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-3206-1
February 22, 2017
linux, linux-ti-omap4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
- linux-ti-omap4: Linux kernel for OMAP4
Details:
It was discovered that a use-after-free vulnerability existed in the block
device layer of the Linux kernel. A local attacker could use this to cause
a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2016-7910)
Dmitry Vyukov discovered a use-after-free vulnerability in the
sys_ioprio_get() function in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-7911)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-123-generic 3.2.0-123.166
linux-image-3.2.0-123-generic-pae 3.2.0-123.166
linux-image-3.2.0-123-highbank 3.2.0-123.166
linux-image-3.2.0-123-omap 3.2.0-123.166
linux-image-3.2.0-123-powerpc-smp 3.2.0-123.166
linux-image-3.2.0-123-powerpc64-smp 3.2.0-123.166
linux-image-3.2.0-123-virtual 3.2.0-123.166
linux-image-3.2.0-1501-omap4 3.2.0-1501.128
linux-image-generic 3.2.0.123.138
linux-image-generic-pae 3.2.0.123.138
linux-image-highbank 3.2.0.123.138
linux-image-omap 3.2.0.123.138
linux-image-omap4 3.2.0.1501.96
linux-image-powerpc-smp 3.2.0.123.138
linux-image-powerpc64-smp 3.2.0.123.138
linux-image-virtual 3.2.0.123.138
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3206-1
CVE-2016-7910, CVE-2016-7911, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-123.166
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1501.128
Ubuntu Security Notice USN-3206-1
February 22, 2017
linux, linux-ti-omap4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
- linux-ti-omap4: Linux kernel for OMAP4
Details:
It was discovered that a use-after-free vulnerability existed in the block
device layer of the Linux kernel. A local attacker could use this to cause
a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2016-7910)
Dmitry Vyukov discovered a use-after-free vulnerability in the
sys_ioprio_get() function in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-7911)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-123-generic 3.2.0-123.166
linux-image-3.2.0-123-generic-pae 3.2.0-123.166
linux-image-3.2.0-123-highbank 3.2.0-123.166
linux-image-3.2.0-123-omap 3.2.0-123.166
linux-image-3.2.0-123-powerpc-smp 3.2.0-123.166
linux-image-3.2.0-123-powerpc64-smp 3.2.0-123.166
linux-image-3.2.0-123-virtual 3.2.0-123.166
linux-image-3.2.0-1501-omap4 3.2.0-1501.128
linux-image-generic 3.2.0.123.138
linux-image-generic-pae 3.2.0.123.138
linux-image-highbank 3.2.0.123.138
linux-image-omap 3.2.0.123.138
linux-image-omap4 3.2.0.1501.96
linux-image-powerpc-smp 3.2.0.123.138
linux-image-powerpc64-smp 3.2.0.123.138
linux-image-virtual 3.2.0.123.138
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3206-1
CVE-2016-7910, CVE-2016-7911, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-123.166
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1501.128
[USN-3208-2] Linux kernel (Xenial HWE) vulnerabilities
==========================================================================
Ubuntu Security Notice USN-3208-2
February 22, 2017
linux-lts-xenial vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty
Details:
USN-3208-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the generic SCSI block layer in the Linux kernel did
not properly restrict write operations in certain situations. A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2016-10088)
CAI Qian discovered that the sysctl implementation in the Linux kernel did
not properly perform reference counting in some situations. An unprivileged
attacker could use this to cause a denial of service (system hang).
(CVE-2016-9191)
Jim Mattson discovered that the KVM implementation in the Linux kernel
mismanages the #BP and #OF exceptions. A local attacker in a guest virtual
machine could use this to cause a denial of service (guest OS crash).
(CVE-2016-9588)
Andy Lutomirski and Willy Tarreau discovered that the KVM implementation in
the Linux kernel did not properly emulate instructions on the SS segment
register. A local attacker in a guest virtual machine could use this to
cause a denial of service (guest OS crash) or possibly gain administrative
privileges in the guest OS. (CVE-2017-2583)
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
improperly emulated certain instructions. A local attacker could use this
to obtain sensitive information (kernel memory). (CVE-2017-2584)
It was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in
the Linux kernel did not properly initialize memory related to logging. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2017-5549)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-4.4.0-64-generic 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-generic-lpae 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-lowlatency 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc-e500mc 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc-smp 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc64-emb 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc64-smp 4.4.0-64.85~14.04.1
linux-image-generic-lpae-lts-xenial 4.4.0.64.50
linux-image-generic-lts-xenial 4.4.0.64.50
linux-image-lowlatency-lts-xenial 4.4.0.64.50
linux-image-powerpc-e500mc-lts-xenial 4.4.0.64.50
linux-image-powerpc-smp-lts-xenial 4.4.0.64.50
linux-image-powerpc64-emb-lts-xenial 4.4.0.64.50
linux-image-powerpc64-smp-lts-xenial 4.4.0.64.50
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3208-2
http://www.ubuntu.com/usn/usn-3208-1
CVE-2016-10088, CVE-2016-9191, CVE-2016-9588, CVE-2017-2583,
CVE-2017-2584, CVE-2017-5549, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-64.85~14.04.1
Ubuntu Security Notice USN-3208-2
February 22, 2017
linux-lts-xenial vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty
Details:
USN-3208-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the generic SCSI block layer in the Linux kernel did
not properly restrict write operations in certain situations. A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2016-10088)
CAI Qian discovered that the sysctl implementation in the Linux kernel did
not properly perform reference counting in some situations. An unprivileged
attacker could use this to cause a denial of service (system hang).
(CVE-2016-9191)
Jim Mattson discovered that the KVM implementation in the Linux kernel
mismanages the #BP and #OF exceptions. A local attacker in a guest virtual
machine could use this to cause a denial of service (guest OS crash).
(CVE-2016-9588)
Andy Lutomirski and Willy Tarreau discovered that the KVM implementation in
the Linux kernel did not properly emulate instructions on the SS segment
register. A local attacker in a guest virtual machine could use this to
cause a denial of service (guest OS crash) or possibly gain administrative
privileges in the guest OS. (CVE-2017-2583)
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
improperly emulated certain instructions. A local attacker could use this
to obtain sensitive information (kernel memory). (CVE-2017-2584)
It was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in
the Linux kernel did not properly initialize memory related to logging. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2017-5549)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-4.4.0-64-generic 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-generic-lpae 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-lowlatency 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc-e500mc 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc-smp 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc64-emb 4.4.0-64.85~14.04.1
linux-image-4.4.0-64-powerpc64-smp 4.4.0-64.85~14.04.1
linux-image-generic-lpae-lts-xenial 4.4.0.64.50
linux-image-generic-lts-xenial 4.4.0.64.50
linux-image-lowlatency-lts-xenial 4.4.0.64.50
linux-image-powerpc-e500mc-lts-xenial 4.4.0.64.50
linux-image-powerpc-smp-lts-xenial 4.4.0.64.50
linux-image-powerpc64-emb-lts-xenial 4.4.0.64.50
linux-image-powerpc64-smp-lts-xenial 4.4.0.64.50
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3208-2
http://www.ubuntu.com/usn/usn-3208-1
CVE-2016-10088, CVE-2016-9191, CVE-2016-9588, CVE-2017-2583,
CVE-2017-2584, CVE-2017-5549, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-64.85~14.04.1
[USN-3208-1] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-3208-1
February 22, 2017
linux, linux-snapdragon vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
- linux-snapdragon: Linux kernel for Snapdragon Processors
Details:
It was discovered that the generic SCSI block layer in the Linux kernel did
not properly restrict write operations in certain situations. A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2016-10088)
CAI Qian discovered that the sysctl implementation in the Linux kernel did
not properly perform reference counting in some situations. An unprivileged
attacker could use this to cause a denial of service (system hang).
(CVE-2016-9191)
Jim Mattson discovered that the KVM implementation in the Linux kernel
mismanages the #BP and #OF exceptions. A local attacker in a guest virtual
machine could use this to cause a denial of service (guest OS crash).
(CVE-2016-9588)
Andy Lutomirski and Willy Tarreau discovered that the KVM implementation in
the Linux kernel did not properly emulate instructions on the SS segment
register. A local attacker in a guest virtual machine could use this to
cause a denial of service (guest OS crash) or possibly gain administrative
privileges in the guest OS. (CVE-2017-2583)
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
improperly emulated certain instructions. A local attacker could use this
to obtain sensitive information (kernel memory). (CVE-2017-2584)
It was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in
the Linux kernel did not properly initialize memory related to logging. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2017-5549)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
linux-image-4.4.0-1048-snapdragon 4.4.0-1048.52
linux-image-4.4.0-64-generic 4.4.0-64.85
linux-image-4.4.0-64-generic-lpae 4.4.0-64.85
linux-image-4.4.0-64-lowlatency 4.4.0-64.85
linux-image-4.4.0-64-powerpc-e500mc 4.4.0-64.85
linux-image-4.4.0-64-powerpc-smp 4.4.0-64.85
linux-image-4.4.0-64-powerpc64-emb 4.4.0-64.85
linux-image-4.4.0-64-powerpc64-smp 4.4.0-64.85
linux-image-generic 4.4.0.64.68
linux-image-generic-lpae 4.4.0.64.68
linux-image-lowlatency 4.4.0.64.68
linux-image-powerpc-e500mc 4.4.0.64.68
linux-image-powerpc-smp 4.4.0.64.68
linux-image-powerpc64-emb 4.4.0.64.68
linux-image-powerpc64-smp 4.4.0.64.68
linux-image-snapdragon 4.4.0.1048.40
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3208-1
CVE-2016-10088, CVE-2016-9191, CVE-2016-9588, CVE-2017-2583,
CVE-2017-2584, CVE-2017-5549, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/4.4.0-64.85
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1048.52
Ubuntu Security Notice USN-3208-1
February 22, 2017
linux, linux-snapdragon vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
- linux-snapdragon: Linux kernel for Snapdragon Processors
Details:
It was discovered that the generic SCSI block layer in the Linux kernel did
not properly restrict write operations in certain situations. A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2016-10088)
CAI Qian discovered that the sysctl implementation in the Linux kernel did
not properly perform reference counting in some situations. An unprivileged
attacker could use this to cause a denial of service (system hang).
(CVE-2016-9191)
Jim Mattson discovered that the KVM implementation in the Linux kernel
mismanages the #BP and #OF exceptions. A local attacker in a guest virtual
machine could use this to cause a denial of service (guest OS crash).
(CVE-2016-9588)
Andy Lutomirski and Willy Tarreau discovered that the KVM implementation in
the Linux kernel did not properly emulate instructions on the SS segment
register. A local attacker in a guest virtual machine could use this to
cause a denial of service (guest OS crash) or possibly gain administrative
privileges in the guest OS. (CVE-2017-2583)
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
improperly emulated certain instructions. A local attacker could use this
to obtain sensitive information (kernel memory). (CVE-2017-2584)
It was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in
the Linux kernel did not properly initialize memory related to logging. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2017-5549)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
linux-image-4.4.0-1048-snapdragon 4.4.0-1048.52
linux-image-4.4.0-64-generic 4.4.0-64.85
linux-image-4.4.0-64-generic-lpae 4.4.0-64.85
linux-image-4.4.0-64-lowlatency 4.4.0-64.85
linux-image-4.4.0-64-powerpc-e500mc 4.4.0-64.85
linux-image-4.4.0-64-powerpc-smp 4.4.0-64.85
linux-image-4.4.0-64-powerpc64-emb 4.4.0-64.85
linux-image-4.4.0-64-powerpc64-smp 4.4.0-64.85
linux-image-generic 4.4.0.64.68
linux-image-generic-lpae 4.4.0.64.68
linux-image-lowlatency 4.4.0.64.68
linux-image-powerpc-e500mc 4.4.0.64.68
linux-image-powerpc-smp 4.4.0.64.68
linux-image-powerpc64-emb 4.4.0.64.68
linux-image-powerpc64-smp 4.4.0.64.68
linux-image-snapdragon 4.4.0.1048.40
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3208-1
CVE-2016-10088, CVE-2016-9191, CVE-2016-9588, CVE-2017-2583,
CVE-2017-2584, CVE-2017-5549, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/4.4.0-64.85
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1048.52
[USN-3207-1] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-3207-1
February 22, 2017
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
It was discovered that a use-after-free vulnerability existed in the block
device layer of the Linux kernel. A local attacker could use this to cause
a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2016-7910)
Dmitry Vyukov discovered a use-after-free vulnerability in the
sys_ioprio_get() function in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-7911)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-110-generic 3.13.0-110.157
linux-image-3.13.0-110-generic-lpae 3.13.0-110.157
linux-image-3.13.0-110-lowlatency 3.13.0-110.157
linux-image-3.13.0-110-powerpc-e500 3.13.0-110.157
linux-image-3.13.0-110-powerpc-e500mc 3.13.0-110.157
linux-image-3.13.0-110-powerpc-smp 3.13.0-110.157
linux-image-3.13.0-110-powerpc64-emb 3.13.0-110.157
linux-image-3.13.0-110-powerpc64-smp 3.13.0-110.157
linux-image-generic 3.13.0.110.118
linux-image-generic-lpae 3.13.0.110.118
linux-image-highbank 3.13.0.110.118
linux-image-lowlatency 3.13.0.110.118
linux-image-powerpc-e500 3.13.0.110.118
linux-image-powerpc-e500mc 3.13.0.110.118
linux-image-powerpc-smp 3.13.0.110.118
linux-image-powerpc64-emb 3.13.0.110.118
linux-image-powerpc64-smp 3.13.0.110.118
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3207-1
CVE-2016-7910, CVE-2016-7911, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-110.157
Ubuntu Security Notice USN-3207-1
February 22, 2017
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
It was discovered that a use-after-free vulnerability existed in the block
device layer of the Linux kernel. A local attacker could use this to cause
a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2016-7910)
Dmitry Vyukov discovered a use-after-free vulnerability in the
sys_ioprio_get() function in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-7911)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-110-generic 3.13.0-110.157
linux-image-3.13.0-110-generic-lpae 3.13.0-110.157
linux-image-3.13.0-110-lowlatency 3.13.0-110.157
linux-image-3.13.0-110-powerpc-e500 3.13.0-110.157
linux-image-3.13.0-110-powerpc-e500mc 3.13.0-110.157
linux-image-3.13.0-110-powerpc-smp 3.13.0-110.157
linux-image-3.13.0-110-powerpc64-emb 3.13.0-110.157
linux-image-3.13.0-110-powerpc64-smp 3.13.0-110.157
linux-image-generic 3.13.0.110.118
linux-image-generic-lpae 3.13.0.110.118
linux-image-highbank 3.13.0.110.118
linux-image-lowlatency 3.13.0.110.118
linux-image-powerpc-e500 3.13.0.110.118
linux-image-powerpc-e500mc 3.13.0.110.118
linux-image-powerpc-smp 3.13.0.110.118
linux-image-powerpc64-emb 3.13.0.110.118
linux-image-powerpc64-smp 3.13.0.110.118
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3207-1
CVE-2016-7910, CVE-2016-7911, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-110.157
[USN-3207-2] Linux kernel (Trusty HWE) vulnerabilities
==========================================================================
Ubuntu Security Notice USN-3207-2
February 22, 2017
linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise
Details:
USN-3207-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that a use-after-free vulnerability existed in the block
device layer of the Linux kernel. A local attacker could use this to cause
a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2016-7910)
Dmitry Vyukov discovered a use-after-free vulnerability in the
sys_ioprio_get() function in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-7911)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.13.0-110-generic 3.13.0-110.157~precise1
linux-image-3.13.0-110-generic-lpae 3.13.0-110.157~precise1
linux-image-generic-lpae-lts-trusty 3.13.0.110.101
linux-image-generic-lts-trusty 3.13.0.110.101
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3207-2
http://www.ubuntu.com/usn/usn-3207-1
CVE-2016-7910, CVE-2016-7911, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-110.157~precise1
Ubuntu Security Notice USN-3207-2
February 22, 2017
linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise
Details:
USN-3207-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 LTS.
It was discovered that a use-after-free vulnerability existed in the block
device layer of the Linux kernel. A local attacker could use this to cause
a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2016-7910)
Dmitry Vyukov discovered a use-after-free vulnerability in the
sys_ioprio_get() function in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2016-7911)
Andrey Konovalov discovered a use-after-free vulnerability in the DCCP
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly gain administrative
privileges. (CVE-2017-6074)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.13.0-110-generic 3.13.0-110.157~precise1
linux-image-3.13.0-110-generic-lpae 3.13.0-110.157~precise1
linux-image-generic-lpae-lts-trusty 3.13.0.110.101
linux-image-generic-lts-trusty 3.13.0.110.101
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
http://www.ubuntu.com/usn/usn-3207-2
http://www.ubuntu.com/usn/usn-3207-1
CVE-2016-7910, CVE-2016-7911, CVE-2017-6074
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-110.157~precise1
Tuesday, February 21, 2017
[USN-3205-1] tcpdump vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCgAGBQJYrIVFAAoJEGVp2FWnRL6TpYQQAKUTUJJF7o/FgtlIjuDEWguW
P5M+/LDf51yWoyiAOv7tWA/gyWhtrB1sB2iIymM44FlLI0358wFaffuY8aqO2D7t
zy22sWbQSrwdzxAScP+fQiiy3UQnmg0XktMqQnADnjnCC795ttuUsylhCMJdAabe
wrAagi7f43P3AB1VNbhR+DVuPBL9FJkBIGpzfDEv7DdFUDo3wbsJ6C743FZIN0w1
K3q7PZaQiTqc73mVw1J/GQ+4twYMT98eZpPKIHxhTWE+Lo3dMl+KhHwIh4UfoFNi
A6XFXALnJNjhJ71QayD1lkarZXuy18Ft+3twsvpBCFG+/Yp/dbr/EHMVOvQTL5aY
RGgHXjhlzwhyEjZBExzUzR4WeT+6TtVk6MHS5HNK2aNMeYqbeyJhHWmLEL5p1gEj
S4BZn3QJ86YXbOzV1p1CJzPOltYJO4fcgvKiZppYg7T9uBmNtSHpbklVEidqRx+W
SVvI6VdEBg24s1DQLCVh974eXm/Le8uX8VdyZl9qOXqGlnpnbzNUoSyluXrnn3nM
rIGInMiVH/5Fgpb4d8krxEcLPmpVugCs5hvOo0uKgZSEraRJLwQXB0/P+ck1V4SZ
0Bm598SbYK6eSXsBDMEFCYPHFQ+n2Yqqc5CEKhZSyOlU0fHX1soIvt7L83MV0km+
IEKGfEyVt+K2IV0r/uta
=oh8Z
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3205-1
February 21, 2017
tcpdump vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
tcpdump could be made to crash or run programs if it received specially
crafted network traffic.
Software Description:
- tcpdump: command-line network traffic analyzer
Details:
It was discovered that tcpdump incorrectly handled certain packets. A
remote attacker could use this issue to cause tcpdump to crash, resulting
in a denial of service, or possibly execute arbitrary code.
In the default installation, attackers would be isolated by the tcpdump
AppArmor profile.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.10:
tcpdump 4.9.0-1ubuntu1~ubuntu16.10.1
Ubuntu 16.04 LTS:
tcpdump 4.9.0-1ubuntu1~ubuntu16.04.1
Ubuntu 14.04 LTS:
tcpdump 4.9.0-1ubuntu1~ubuntu14.04.1
Ubuntu 12.04 LTS:
tcpdump 4.9.0-1ubuntu1~ubuntu12.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
http://www.ubuntu.com/usn/usn-3205-1
CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925,
CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929,
CVE-2016-7930, CVE-2016-7931, CVE-2016-7932, CVE-2016-7933,
CVE-2016-7934, CVE-2016-7935, CVE-2016-7936, CVE-2016-7937,
CVE-2016-7938, CVE-2016-7939, CVE-2016-7940, CVE-2016-7973,
CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984,
CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993,
CVE-2016-8574, CVE-2016-8575, CVE-2017-5202, CVE-2017-5203,
CVE-2017-5204, CVE-2017-5205, CVE-2017-5341, CVE-2017-5342,
CVE-2017-5482, CVE-2017-5483, CVE-2017-5484, CVE-2017-5485,
CVE-2017-5486
Package Information:
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu16.10.1
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu16.04.1
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu14.04.1
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu12.04.1
Version: GnuPG v2
iQIcBAEBCgAGBQJYrIVFAAoJEGVp2FWnRL6TpYQQAKUTUJJF7o/FgtlIjuDEWguW
P5M+/LDf51yWoyiAOv7tWA/gyWhtrB1sB2iIymM44FlLI0358wFaffuY8aqO2D7t
zy22sWbQSrwdzxAScP+fQiiy3UQnmg0XktMqQnADnjnCC795ttuUsylhCMJdAabe
wrAagi7f43P3AB1VNbhR+DVuPBL9FJkBIGpzfDEv7DdFUDo3wbsJ6C743FZIN0w1
K3q7PZaQiTqc73mVw1J/GQ+4twYMT98eZpPKIHxhTWE+Lo3dMl+KhHwIh4UfoFNi
A6XFXALnJNjhJ71QayD1lkarZXuy18Ft+3twsvpBCFG+/Yp/dbr/EHMVOvQTL5aY
RGgHXjhlzwhyEjZBExzUzR4WeT+6TtVk6MHS5HNK2aNMeYqbeyJhHWmLEL5p1gEj
S4BZn3QJ86YXbOzV1p1CJzPOltYJO4fcgvKiZppYg7T9uBmNtSHpbklVEidqRx+W
SVvI6VdEBg24s1DQLCVh974eXm/Le8uX8VdyZl9qOXqGlnpnbzNUoSyluXrnn3nM
rIGInMiVH/5Fgpb4d8krxEcLPmpVugCs5hvOo0uKgZSEraRJLwQXB0/P+ck1V4SZ
0Bm598SbYK6eSXsBDMEFCYPHFQ+n2Yqqc5CEKhZSyOlU0fHX1soIvt7L83MV0km+
IEKGfEyVt+K2IV0r/uta
=oh8Z
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3205-1
February 21, 2017
tcpdump vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
tcpdump could be made to crash or run programs if it received specially
crafted network traffic.
Software Description:
- tcpdump: command-line network traffic analyzer
Details:
It was discovered that tcpdump incorrectly handled certain packets. A
remote attacker could use this issue to cause tcpdump to crash, resulting
in a denial of service, or possibly execute arbitrary code.
In the default installation, attackers would be isolated by the tcpdump
AppArmor profile.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.10:
tcpdump 4.9.0-1ubuntu1~ubuntu16.10.1
Ubuntu 16.04 LTS:
tcpdump 4.9.0-1ubuntu1~ubuntu16.04.1
Ubuntu 14.04 LTS:
tcpdump 4.9.0-1ubuntu1~ubuntu14.04.1
Ubuntu 12.04 LTS:
tcpdump 4.9.0-1ubuntu1~ubuntu12.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
http://www.ubuntu.com/usn/usn-3205-1
CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925,
CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929,
CVE-2016-7930, CVE-2016-7931, CVE-2016-7932, CVE-2016-7933,
CVE-2016-7934, CVE-2016-7935, CVE-2016-7936, CVE-2016-7937,
CVE-2016-7938, CVE-2016-7939, CVE-2016-7940, CVE-2016-7973,
CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984,
CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993,
CVE-2016-8574, CVE-2016-8575, CVE-2017-5202, CVE-2017-5203,
CVE-2017-5204, CVE-2017-5205, CVE-2017-5341, CVE-2017-5342,
CVE-2017-5482, CVE-2017-5483, CVE-2017-5484, CVE-2017-5485,
CVE-2017-5486
Package Information:
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu16.10.1
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu16.04.1
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu14.04.1
https://launchpad.net/ubuntu/+source/tcpdump/4.9.0-1ubuntu1~ubuntu12.04.1
Subscribe to:
Posts (Atom)