Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 16.04 LTS: 3099-4 Moderate: Linux Kernel Denial Of Service

ubuntu
Calendar Grey October 11, 2016
Scroller Ubuntu
Numerous security patches released for Ubuntu 16.04 LTS addressing linux-snapdragon kernel weaknesses. Maintain your security!
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux-snapdragon: Linux kernel for Snapdragon Processors

Details:

Vladimír Beneš discovered an unbounded recursion in the VLAN and TEB

Generic Receive Offload (GRO) processing implementations in the Linux

kernel, A remote attacker could use this to cause a stack corruption,

leading to a denial of service (system crash). (CVE-2016-7039)

Marco Grassi discovered a use-after-free condition could occur in the TCP

retransmit queue handling code in the Linux kernel. A local attacker could

use this to cause a denial of service (system crash) or possibly execute

arbitrary code. (CVE-2016-6828)

Pengfei Wang discovered a race condition in the Adaptec AAC RAID controller

driver in the Linux kernel when handling ioctl()s. A local attacker could

use this to cause a denial of service (system crash). (CVE-2016-6480)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  linux-image-4.4.0-1030-snapdragon  4.4.0-1030.33

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References

https://ubuntu.com/security/notices/USN-3099-4

https://ubuntu.com/security/notices/USN-3099-1

CVE-2016-6480, CVE-2016-6828, CVE-2016-7039

October 11, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.