Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Jann Horn discovered that the Berkeley Packet Filter (BPF) implementation
in the Linux kernel improperly performed sign extension in some situations.
A local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-16995)
It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-0861)
It was discovered that a use-after-free vulnerability existed in the
network namespaces implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2017-15129)
It was discovered that the netfilter component of the Linux did not
properly restrict acce...
The problem can be corrected by updating your livepatches to the following versions: | Kernel | Version | flavors | |-----------------+----------+--------------------------| | 4.4.0-116.140 | 37.2 | generic, lowlatency | | 4.4.0-119.143 | 37.2 | generic, lowlatency | | 4.4.0-121.145 | 37.2 | generic, lowlatency | | 4.4.0-122.146 | 37.2 | generic, lowlatency | | 4.4.0-116.140~14.04.1 | 37.2 | generic, lowlatency | | 4.4.0-119.143~14.04.1 | 37.2 | generic, lowlatency | | 4.4.0-121.145~14.04.1 | 37.2 | generic, lowlatency | Additionally, you should install an updated kernel with these fixes and reboot at your convienience.
CVE-2017-0861, CVE-2017-15129, CVE-2017-16995, CVE-2017-17448,
CVE-2017-17450, CVE-2018-1000199, CVE-2018-5333, CVE-2018-5344,
CVE-2018-8043
--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Get the latest Linux and open source security news straight to your inbox.