Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 12.10 USN-2138-1 High: Kernel Flaws Enable Potential Attacks

ubuntu
Calendar Grey March 7, 2014
Scroller Ubuntu
Essential patches for Ubuntu's Linux core rectify various security flaws; ensure to act promptly for protecting your system.
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux: Linux kernel

Details:

Mathy Vanhoef discovered an error in the the way the ath9k driver was

handling the BSSID masking. A remote attacker could exploit this error to

discover the original MAC address after a spoofing atack. (CVE-2013-4579)

Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu

function of the Kernel Virtual Machine (KVM) subsystem. A local user could

exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)

Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel

Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could

exploit this flaw to cause a denial of service or host OS system crash.

(CVE-2013-6367)

Andrew Honig reported an error in the Linux Kernel's Kernel Virtual Machine

(KVM) VAPIC synchronization operation. A local user could exploit this flaw

to gain privileges or cause a de...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  linux-image-3.5.0-47-generic    3.5.0-47.71
  linux-image-3.5.0-47-highbank   3.5.0-47.71
  linux-image-3.5.0-47-omap       3.5.0-47.71
  linux-image-3.5.0-47-powerpc-smp  3.5.0-47.71
  linux-image-3.5.0-47-powerpc64-smp  3.5.0-47.71

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References

https://ubuntu.com/security/notices/USN-2138-1

CVE-2013-4579, CVE-2013-4587, CVE-2013-6367, CVE-2013-6368,

CVE-2013-6382, CVE-2013-7263, CVE-2013-7264, CVE-2013-7265,

CVE-2013-7266, CVE-2013-7267, CVE-2013-7268, CVE-2013-7269,

CVE-2013-7270, CVE-2013-7271, CVE-2013-7281, CVE-2014-1438,

CVE-2014-1446, CVE-2014-1874

March 07, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.