Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 8.04 LTS USN-1146-1 Moderate: Kernel Exploits and Fixes

ubuntu
Calendar Grey June 9, 2011
Scroller Ubuntu
Several vulnerabilities within the Linux kernel are present in Ubuntu 8.04 LTS. It is crucial for users to apply updates for enhanced security.
Multiple flaws fixed in the Linux kernel.

Summary

Multiple flaws fixed in the Linux kernel.

Software Description:

- linux: Linux kernel

Details:

Kees Cook discovered that some ethtool functions did not correctly clear

heap memory. A local attacker with CAP_NET_ADMIN privileges could exploit

this to read portions of kernel heap memory, leading to a loss of privacy.

(CVE-2010-4655)

Kees Cook discovered that the IOWarrior USB device driver did not correctly

check certain size fields. A local attacker with physical access could plug

in a specially crafted USB device to crash the system or potentially gain

root privileges. (CVE-2010-4656)

Goldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly

clear memory when writing certain file holes. A local attacker could

exploit this to read uninitialized data from the disk, leading to a loss of

privacy. (CVE-2011-0463)

Jens Kuehnel discovered that the InfiniBand driver contained a race

condition. On systems using InfiniBand, a local attacker could send

specially crafted r...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 8.04 LTS:
  linux-image-2.6.24-29-386       2.6.24-29.90
  linux-image-2.6.24-29-generic   2.6.24-29.90
  linux-image-2.6.24-29-hppa32    2.6.24-29.90
  linux-image-2.6.24-29-hppa64    2.6.24-29.90
  linux-image-2.6.24-29-itanium   2.6.24-29.90
  linux-image-2.6.24-29-lpia      2.6.24-29.90
  linux-image-2.6.24-29-lpiacompat  2.6.24-29.90
  linux-image-2.6.24-29-mckinley  2.6.24-29.90
  linux-image-2.6.24-29-openvz    2.6.24-29.90
  linux-image-2.6.24-29-powerpc   2.6.24-29.90
  linux-image-2.6.24-29-powerpc-smp  2.6.24-29.90
  linux-image-2.6.24-29-powerpc64-smp  2.6.24-29.90
  linux-image-2.6.24-29-rt        2.6.24-29.90
  linux-image-2.6.24-29-server    2.6.24-29.90
  linux-image-2.6.24-29-sparc64   2.6.24-29.90
  linux-image-2.6.24-29-sparc64-smp  2.6.24-29.90
  linux-image-2.6.24-29-virtual   2.6.24-29.90
  linux-image-2.6.24-29-xen       2.6.24-29.90

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

CVE-2010-4655, CVE-2010-4656, CVE-2011-0463, CVE-2011-0695,

CVE-2011-0712, CVE-2011-1012, CVE-2011-1017, CVE-2011-1593

June 09, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.