Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple kernel flaws have been fixed.
Software Description:
- linux: Linux kernel
Details:
Dan Rosenberg discovered that the Linux kernel TIPC implementation
contained multiple integer signedness errors. A local attacker could
exploit this to gain root privileges. (CVE-2010-3859)
Dan Rosenberg discovered that the CAN protocol on 64bit systems did not
correctly calculate the size of certain buffers. A local attacker could
exploit this to crash the system or possibly execute arbitrary code as the
root user. (CVE-2010-3874)
Vasiliy Kulikov discovered that the Linux kernel X.25 implementation did
not correctly clear kernel memory. A local attacker could exploit this to
read kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)
Vasiliy Kulikov discovered that the Linux kernel sockets implementation did
not properly initialize certain structures. A local attacker could exploit
this to read kernel stack memory, leading to a loss of privacy.
(CVE...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: linux-image-2.6.38-10-generic 2.6.38-10.46 linux-image-2.6.38-10-generic-pae 2.6.38-10.46 linux-image-2.6.38-10-omap 2.6.38-10.46 linux-image-2.6.38-10-powerpc 2.6.38-10.46 linux-image-2.6.38-10-powerpc-smp 2.6.38-10.46 linux-image-2.6.38-10-powerpc64-smp 2.6.38-10.46 linux-image-2.6.38-10-server 2.6.38-10.46 linux-image-2.6.38-10-versatile 2.6.38-10.46 linux-image-2.6.38-10-virtual 2.6.38-10.46 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well.
https://ubuntu.com/security/notices/USN-1167-1
CVE-2010-3859, CVE-2010-3874, CVE-2010-3875, CVE-2010-3876,
CVE-2010-3877, CVE-2010-3880, CVE-2010-4158, CVE-2010-4162,
CVE-2010-4163, CVE-2010-4164, CVE-2010-4165, CVE-2010-4169,
CVE-2010-4175, CVE-2010-4243, CVE-2010-4248, CVE-2010-4249,
CVE-2010-4256, CVE-2010-4258, CVE-2010-4342, CVE-2010-4346,
CVE-2010-4527, CVE-2010-4529, CVE-2010-4565, CVE-2010-4649,
CVE-2010-4668, CVE-2011-0463, CVE-2011-0521, CVE-2011-0695,
CVE-2011-0711, CVE-2011-0712, CVE-2011-0726, CVE-2011-0999,
CVE-2011-1010, CVE-2011-1012, CVE-2011-1013, CVE-2011-1016,
CVE-2011-1017, CVE-2011-1019, CVE-2011-1044, CVE-2011-1076,
Get the latest Linux and open source security news straight to your inbox.