Alerts This Week
Warning Icon 1 929
Alerts This Week
Warning Icon 1 929

Debian: DLA-2241-2 Critical: Linux Kernel Security Update

debian lts
Calendar Grey June 10, 2020
Dist Debian Esm H88
Essential enhancements to the Linux kernel in Debian LTS address multiple vulnerabilities that could pose security threats and exploitation opportunities.
This update is now available for all supported architectures

Summary

CVE-2015-8839

A race condition was found in the ext4 filesystem implementation.
A local user could exploit this to cause a denial of service
(filesystem corruption).

CVE-2018-14610, CVE-2018-14611, CVE-2018-14612, CVE-2018-14613

Wen Xu from SSLab at Gatech reported that crafted Btrfs volumes
could trigger a crash (Oops) and/or out-of-bounds memory access.
An attacker able to mount such a volume could use this to cause a
denial of service or possibly for privilege escalation.

CVE-2019-5108

Mitchell Frank of Cisco discovered that when the IEEE 802.11
(WiFi) stack was used in AP mode with roaming, it would trigger
roaming for a newly associated station before the station was
authenticated. An attacker within range of the AP could use this
to cause a denial of service, either by filling up a switching
table or by redirecting traffic away from other stations.

CVE-2019-19319

Jungyeon discovered that a crafted filesystem can cause the ext4

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: linux
Version: 3.16.84-1
CVE ID: CVE-2015-8839 CVE-2018-14610 CVE-2018-14611 CVE-2018-14612

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here