Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 3.2.57-3+deb7u1 Critical: Kernel DoS And Escalation Fix

debian
Calendar Grey May 12, 2014
Debian Logo
Debian DSA-2927-1 informs users of essential updates addressing significant security flaws related to denial of service and privilege escalation risks.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, information leaks or privilege escalation:

Summary

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service, information leaks or privilege
escalation:

CVE-2014-0196

Jiri Slaby discovered a race condition in the pty layer, which could
lead to denial of service or privilege escalation.

CVE-2014-1737 / CVE-2014-1738

Matthew Daley discovered that missing input sanitising in the
FDRAWCMD ioctl and an information leak could result in privilege
escalation.

CVE-2014-2851

Incorrect reference counting in the ping_init_sock() function allows
denial of service or privilege escalation.

CVE-2014-3122

Incorrect locking of memory can result in local denial of service.

For the stable distribution (wheezy), these problems have been fixed in
version 3.2.57-3+deb7u1. This update also fixes a regression in the isci
driver and suspend problems with certain AMD CPUs (introduced in the
updated kernel from the Wheezy 7.5 point release).

For the unstable distribution (sid), these problems will be f...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2014-0196 CVE-2014-1737 CVE-2014-1738 CVE-2014-2851

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here