Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian: DSA-1996-1 High: Linux Kernel Privilege Escalation and DoS Risks

debian
Calendar Grey February 13, 2010
Debian Logo
Ubuntu Security Notice USN-1996-1 resolves significant vulnerabilities in the 2.6 kernel impacting various platforms.
CVE-2009-3939 Joseph Malicki reported that the dbg_lvl sysfs attribute for the megaraid_sas device driver had world-writable permissions,

Summary


Several vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service, sensitive memory leak or privilege
escalation. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2009-3939

Joseph Malicki reported that the dbg_lvl sysfs attribute for the
megaraid_sas device driver had world-writable permissions,
permitting local users to modify logging settings.

CVE-2009-4027

Lennert Buytenhek reported a race in the mac80211 subsystem that
may allow remote users to cause a denial of service (system crash)
on a system connected to the same wireless network.

CVE-2009-4536 & CVE-2009-4538

Fabian Yamaguchi reported issues in the e1000 and e1000e drivers for Intel gigabit network adapters which allow remote users to
bypass packet filters using specially crafted ethernet frames.

CVE-2010-0003

Andi Kleen reported a defect which allows local users to gain read
access to memory reachable...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux-2.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here