Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-3448-1 Critical: Linux Kernel Privilege Escalation And DoS

debian
Calendar Grey January 19, 2016
Debian Logo
Debian Security Notice DSA-3450-1 details essential updates to the kernel addressing vulnerabilities related to privilege escalation and denial of service threats.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation or denial-of-service

Summary

CVE-2013-4312

Tetsuo Handa discovered that it is possible for a process to open
far more files than the process' limit leading to denial-of-service
conditions.

CVE-2015-7566

Ralf Spenneberg of OpenSource Security reported that the visor
driver crashes when a specially crafted USB device without bulk-out
endpoint is detected.

CVE-2015-8767

An SCTP denial-of-service was discovered which can be triggered by a
local attacker during a heartbeat timeout event after the 4-way
handshake.

CVE-2016-0723

A use-after-free vulnerability was discovered in the TIOCGETD ioctl.
A local attacker could use this flaw for denial-of-service.

CVE-2016-0728

The Perception Point research team discovered a use-after-free
vulnerability in the keyring facility, possibly leading to local
privilege escalation.

For the stable distribution (jessie), these problems have been fixed in
version 3.16.7-ckt20-1+deb8u3.

We recommend that you upgrade your linux packages.

Further informati...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2013-4312 CVE-2015-7566 CVE-2015-8767 CVE-2016-0723

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here