Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian 3.2: DSA-3094-1 Critical: Linux Kernel Service Denial Exploit

debian
Calendar Grey December 8, 2014
Debian Logo
On January 15, 2015, Ubuntu addressed multiple security flaws in the kernel that posed risks of service interruption and unauthorized privilege elevation.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation: CVE-2014-7841

Summary

CVE-2014-7841

Liu Wei of Red Hat discovered that a SCTP server doing ASCONF will
panic on malformed INIT chunks by triggering a NULL pointer
dereference.

CVE-2014-8369

A flaw was discovered in the way iommu mapping failures were handled
in the kvm_iommu_map_pages() function in the Linux kernel. A guest
OS user could exploit this flaw to cause a denial of service (host
OS memory corruption) or possibly have other unspecified impact on
the host OS.

CVE-2014-8884

A stack-based buffer overflow flaw was discovered in the
TechnoTrend/Hauppauge DEC USB driver. A local user with write access
to the corresponding device could use this flaw to crash the kernel
or, potentially, elevate their privileges.

CVE-2014-9090

Andy Lutomirski discovered that the do_double_fault function in
arch/x86/kernel/traps.c in the Linux kernel did not properly handle
faults associated with the Stack Segment (SS) segment register,
which allows local users to cause a deni...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2014-7841 CVE-2014-8369 CVE-2014-8884 CVE-2014-9090

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here