Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-3396-1 Severe Denial of Service Vulnerability in Linux Kernel

debian
Calendar Grey November 10, 2015
Debian Logo
Uncover vital security advisories for Debian Linux addressing potential denial of service threats and kernel weaknesses.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service

Summary

CVE-2015-5307

Ben Serebrin from Google discovered a guest to host denial of
service flaw affecting the KVM hypervisor. A malicious guest can
trigger an infinite stream of "alignment check" (#AC) exceptions
causing the processor microcode to enter an infinite loop where the
core never receives another interrupt. This leads to a panic of the
host kernel.

CVE-2015-7833

Sergej Schumilo, Hendrik Schwartke and Ralf Spenneberg discovered a
flaw in the processing of certain USB device descriptors in the
usbvision driver. An attacker with physical access to the system can
use this flaw to crash the system.

CVE-2015-7872

Dmitry Vyukov discovered a vulnerability in the keyrings garbage
collector allowing a local user to trigger a kernel panic.

CVE-2015-7990

It was discovered that the fix for CVE-2015-6937 was incomplete. A
race condition when sending a message on unbound socket can still
cause a NULL pointer dereference. A remote attacker might be able to
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2015-5307 CVE-2015-7833 CVE-2015-7872 CVE-2015-7990

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here