Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Ubuntu 12.04 LTS: USN-2113-1 Moderate: Linux Kernel Security Flaws

ubuntu
Calendar Grey February 19, 2014
Scroller Ubuntu
Patches for various kernel vulnerabilities in Ubuntu 12.04; guarantees improved protection and operational reliability post-updates.
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux-lts-saucy: Linux hardware enablement kernel from Saucy

Details:

Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in

the Linux kernel. A remote attacker could exploit this flaw to cause a

denial of service (panic). (CVE-2013-4563)

Mathy Vanhoef discovered an error in the the way the ath9k driver was

handling the BSSID masking. A remote attacker could exploit this error to

discover the original MAC address after a spoofing atack. (CVE-2013-4579)

Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu

function of the Kernel Virtual Machine (KVM) subsystem. A local user could

exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)

Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel

Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could

exploit this flaw to cause a denial of servi...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  linux-image-3.11.0-17-generic   3.11.0-17.31~precise1
  linux-image-3.11.0-17-generic-lpae  3.11.0-17.31~precise1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References

https://ubuntu.com/security/notices/USN-2113-1

CVE-2013-4563, CVE-2013-4579, CVE-2013-4587, CVE-2013-6367,

CVE-2013-6368, CVE-2013-6376, CVE-2013-6382, CVE-2013-6432,

CVE-2013-7263, CVE-2013-7264, CVE-2013-7265, CVE-2013-7266,

CVE-2013-7267, CVE-2013-7268, CVE-2013-7269, CVE-2013-7270,

CVE-2013-7271, CVE-2013-7281, CVE-2014-1438, CVE-2014-1446

February 18, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.