Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Ubuntu 10.04 LTS: Critical Kernel Memory Leak Fixes and Exploits Overview

ubuntu
Calendar Grey April 8, 2013
Scroller Ubuntu
Urgent vulnerabilities addressed in Ubuntu 10.04 LTS via kernel patches. Protect your device immediately!
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux: Linux kernel

Details:

Mathias Krause discovered several errors in the Linux kernel's xfrm_user

implementation. A local attacker could exploit these flaws to examine parts

of kernel memory. (CVE-2012-6537)

Mathias Krause discovered information leak in the Linux kernel's compat

ioctl interface. A local user could exploit the flaw to examine parts of

kernel stack memory (CVE-2012-6539)

Mathias Krause discovered an information leak in the Linux kernel's

getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw

to examine parts of kernel stack memory. (CVE-2012-6540)

Emese Revfy discovered that in the Linux kernel signal handlers could leak

address information across an exec, making it possible to by pass ASLR

(Address Space Layout Randomization). A local user could use this flaw to

by pass ASLR to reliably deliver an exploit payload that would otherwise be

stop...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  linux-image-2.6.32-46-386       2.6.32-46.107
  linux-image-2.6.32-46-generic   2.6.32-46.107
  linux-image-2.6.32-46-generic-pae  2.6.32-46.107
  linux-image-2.6.32-46-ia64      2.6.32-46.107
  linux-image-2.6.32-46-lpia      2.6.32-46.107
  linux-image-2.6.32-46-powerpc   2.6.32-46.107
  linux-image-2.6.32-46-powerpc-smp  2.6.32-46.107
  linux-image-2.6.32-46-powerpc64-smp  2.6.32-46.107
  linux-image-2.6.32-46-preempt   2.6.32-46.107
  linux-image-2.6.32-46-server    2.6.32-46.107
  linux-image-2.6.32-46-sparc64   2.6.32-46.107
  linux-image-2.6.32-46-sparc64-smp  2.6.32-46.107
  linux-image-2.6.32-46-versatile  2.6.32-46.107
  linux-image-2.6.32-46-virtual   2.6.32-46.107

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1792-1

CVE-2012-6537, CVE-2012-6539, CVE-2012-6540, CVE-2013-0914,

CVE-2013-1767, CVE-2013-1792

Severity
critical
Lowest
Low
Medium
High
Critical

April 08, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.