Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 8: DSA-3503-1 Critical: Kernel Denial Of Service Issues

debian
Calendar Grey March 3, 2016
Debian Logo
Debian DSA-3510-1 tackles vulnerabilities in the kernel and provides suggestions for enhancing security and system reliability.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, information leak or data loss

Summary

CVE-2013-4312

Tetsuo Handa discovered that users can use pipes queued on local
(Unix) sockets to allocate an unfair share of kernel memory, leading
to denial-of-service (resource exhaustion).

This issue was previously mitigated for the stable suite by limiting
the total number of files queued by each user on local sockets. The
new kernel version in both suites includes that mitigation plus
limits on the total size of pipe buffers allocated for each user.

CVE-2015-7566

Ralf Spenneberg of OpenSource Security reported that the visor
driver crashes when a specially crafted USB device without bulk-out
endpoint is detected.

CVE-2015-8767

An SCTP denial-of-service was discovered which can be triggered by a
local attacker during a heartbeat timeout event after the 4-way
handshake.

CVE-2015-8785

It was discovered that local users permitted to write to a file on a
FUSE filesystem could cause a denial of service (unkillable loop in
the kernel).

CVE-2...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2013-4312 CVE-2015-7566 CVE-2015-8767 CVE-2015-8785

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here