Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 10.04 LTS USN-1725-1 Moderate: Xen Stack Corruption Kernel Risk

ubuntu
Calendar Grey February 14, 2013
Scroller Ubuntu
The Ubuntu Security Notice USN-1725-2 outlines a critical flaw in the kernel that may result in instability and system failures in certain scenarios.
The system could be made to crash under certain conditions.

Summary

The system could be made to crash under certain conditions.

Software Description:

- linux: Linux kernel

Details:

Andrew Cooper of Citrix reported a Xen stack corruption in the Linux

kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest

kernel to crash, or operate erroneously.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  linux-image-2.6.32-45-386       2.6.32-45.103
  linux-image-2.6.32-45-generic   2.6.32-45.103
  linux-image-2.6.32-45-generic-pae  2.6.32-45.103
  linux-image-2.6.32-45-ia64      2.6.32-45.103
  linux-image-2.6.32-45-lpia      2.6.32-45.103
  linux-image-2.6.32-45-powerpc   2.6.32-45.103
  linux-image-2.6.32-45-powerpc-smp  2.6.32-45.103
  linux-image-2.6.32-45-powerpc64-smp  2.6.32-45.103
  linux-image-2.6.32-45-preempt   2.6.32-45.103
  linux-image-2.6.32-45-server    2.6.32-45.103
  linux-image-2.6.32-45-sparc64   2.6.32-45.103
  linux-image-2.6.32-45-sparc64-smp  2.6.32-45.103
  linux-image-2.6.32-45-versatile  2.6.32-45.103
  linux-image-2.6.32-45-virtual   2.6.32-45.103

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1725-1

CVE-2013-0190

February 14, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.