Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 10.10 USN-1243-1 Critical: Kernel Denial of Service Threats

ubuntu
Calendar Grey October 25, 2011
Scroller Ubuntu
Serious security flaws have been patched in the kernel affecting Ubuntu 10.10. Ensure you update your system to safeguard against potential threats.
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux: Linux kernel

Details:

It was discovered that the security fix for CVE-2010-4250 introduced a

regression. A remote attacker could exploit this to crash the system,

leading to a denial of service. (CVE-2011-1479)

Vasiliy Kulikov discovered that taskstats did not enforce access

restrictions. A local attacker could exploit this to read certain

information, leading to a loss of privacy. (CVE-2011-2494)

Vasiliy Kulikov discovered that /proc/PID/io did not enforce access

restrictions. A local attacker could exploit this to read certain

information, leading to a loss of privacy. (CVE-2011-2495)

It was discovered that the EXT4 filesystem contained multiple off-by-one

flaws. A local attacker could exploit this to crash the system, leading to

a denial of service. (CVE-2011-2695)

Christian Ohm discovered that the perf command looks for configuration

files in the current directory. I...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
  linux-image-2.6.35-30-generic   2.6.35-30.61
  linux-image-2.6.35-30-generic-pae  2.6.35-30.61
  linux-image-2.6.35-30-omap      2.6.35-30.61
  linux-image-2.6.35-30-powerpc   2.6.35-30.61
  linux-image-2.6.35-30-powerpc-smp  2.6.35-30.61
  linux-image-2.6.35-30-powerpc64-smp  2.6.35-30.61
  linux-image-2.6.35-30-server    2.6.35-30.61
  linux-image-2.6.35-30-versatile  2.6.35-30.61
  linux-image-2.6.35-30-virtual   2.6.35-30.61

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1243-1

CVE-2011-1479, CVE-2011-2494, CVE-2011-2495, CVE-2011-2695,

CVE-2011-2905, CVE-2011-2909, CVE-2011-3188, CVE-2011-3363

Severity
critical
Lowest
Low
Medium
High
Critical

October 25, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.