Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 10.10 USN-1244-1 Moderate: linux-ti-omap4 Denial of Service

ubuntu
Calendar Grey October 25, 2011
Scroller Ubuntu
Several security flaws resolved in Ubuntu 10.10 concerning the Linux kernel for OMAP4, necessitating prompt updates.
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux-ti-omap4: Linux kernel for OMAP4

Details:

Dan Rosenberg discovered that the Linux kernel X.25 implementation

incorrectly parsed facilities. A remote attacker could exploit this to

crash the kernel, leading to a denial of service. (CVE-2010-3873)

Andrea Righi discovered a race condition in the KSM memory merging support.

If KSM was being used, a local attacker could exploit this to crash the

system, leading to a denial of service. (CVE-2011-2183)

Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly

handled unlock requests. A local attacker could exploit this to cause a

denial of service. (CVE-2011-2491)

Vasiliy Kulikov discovered that taskstats did not enforce access

restrictions. A local attacker could exploit this to read certain

information, leading to a loss of privacy. (CVE-2011-2494)

Vasiliy Kulikov discovered that /proc/PID/io did not enforce access

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
  linux-image-2.6.35-903-omap4    2.6.35-903.26

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1244-1

CVE-2010-3873, CVE-2011-2183, CVE-2011-2491, CVE-2011-2494,

CVE-2011-2495, CVE-2011-2517, CVE-2011-2695, CVE-2011-2905,

CVE-2011-2909, CVE-2011-3363

October 25, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.