Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Ubuntu 13.10 USN-2049-1 Critical: Kernel Access and DoS Issues

ubuntu
Calendar Grey December 7, 2013
Scroller Ubuntu
The Ubuntu 13.10 kernel shows critical vulnerabilities, allowing unauthorized access and potential information leaks, urging users to apply security updates promptly
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux: Linux kernel

Details:

Miroslav Vadkerti discovered a flaw in how the permissions for network

sysctls are handled in the Linux kernel. An unprivileged local user could

exploit this flaw to have privileged access to files in /proc/sys/net/.

(CVE-2013-4270)

A flaw was discovered in the Linux kernel's dm snapshot facility. A remote

authenticated user could exploit this flaw to obtain sensitive information

or modify/corrupt data. (CVE-2013-4299)

Wannes Rombouts reported a vulnerability in the networking tuntap interface

of the Linux kernel. A local user with the CAP_NET_ADMIN capability could

leverage this flaw to gain full admin privileges. (CVE-2013-4343)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission

Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this

flaw to obtain sensitive information by sniffing network traffic.

(CVE-2013-4350)

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  linux-image-3.11.0-14-generic   3.11.0-14.21
  linux-image-3.11.0-14-generic-lpae  3.11.0-14.21

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References

https://ubuntu.com/security/notices/USN-2049-1

CVE-2013-4270, CVE-2013-4299, CVE-2013-4343, CVE-2013-4350,

CVE-2013-4387, CVE-2013-4470

Severity
critical
Lowest
Low
Medium
High
Critical

December 07, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.