Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian DSA-3696-1 Critical: Local Denial Of Service Threats

debian
Calendar Grey October 19, 2016
Debian Logo
Ubuntu bulletin USN-4696-1 provides vital information on severe vulnerabilities in the Linux kernel that pose risks to system integrity. Immediate update advised for user protection.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

CVE-2015-8956

It was discovered that missing input sanitising in RFCOMM Bluetooth
socket handling may result in denial of service or information leak.

CVE-2016-5195

It was discovered that a race condition in the memory management
code can be used for local privilege escalation.

CVE-2016-7042

Ondrej Kozina discovered that incorrect buffer allocation in the
proc_keys_show() function may result in local denial of service.

CVE-2016-7425

Marco Grassi discovered a buffer overflow in the arcmsr SCSI driver
which may result in local denial of service, or potentially,
arbitrary code execution.

Additionally this update fixes a regression introduced in DSA-3616-1
causing iptables performance issues (cf. Debian Bug #831014).

For the stable distribution (jessie), these problems have been fixed in
version 3.16.36-1+deb8u2.

We recommend that you upgrade your linux packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequent...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2015-8956 CVE-2016-5195 CVE-2016-7042 CVE-2016-7425

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here