Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Ubuntu 12.04 ESM USN-3655-2 Severe: Linux Kernel Denial of Service

ubuntu
Calendar Grey May 22, 2018
Scroller Ubuntu
Crucial revisions for Ubuntu's Linux core tackling various vulnerabilities impacting Trusty and Precise ESM.
Several security issues were addressed in the Linux kernel.

Summary

Several security issues were addressed in the Linux kernel.

Software Description:

- linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise ESM

Details:

USN-3655-1 fixed vulnerabilities and added mitigations in the Linux

kernel for Ubuntu 14.04 LTS. This update provides the corresponding

updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu

14.04 LTS for Ubuntu 12.04 ESM.

Jann Horn and Ken Johnson discovered that microprocessors utilizing

speculative execution of a memory read may allow unauthorized memory

reads via a sidechannel attack. This flaw is known as Spectre

Variant 4. A local attacker could use this to expose sensitive

information, including kernel memory. (CVE-2018-3639)

Jan H. Schönherr discovered that the Xen subsystem did not properly handle

block IO merges correctly in some situations. An attacker in a guest vm

could use this to cause a denial of service (host crash) or possibly gain

administrative privilege...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  linux-image-3.13.0-149-generic  3.13.0-149.199~precise1
  linux-image-3.13.0-149-generic-lpae  3.13.0-149.199~precise1
  linux-image-generic-lpae-lts-trusty  3.13.0.149.140
  linux-image-generic-lts-trusty  3.13.0.149.140

Please note that fully mitigating CVE-2018-3639 (Spectre Variant 4)
may require corresponding processor microcode/firmware updates or,
in virtual environments, hypervisor updates. On i386 and amd64
architectures, the SSBD feature is required to enable the kernel
mitigations. BIOS vendors will be making updates available for Intel
processors that implement SSBD. Ubuntu users with a processor from
a different vendor should contact the vendor to identify necessary
firmware updates. Ubuntu users in cloud environments should contact
the cloud provider to confirm that the hypervisor has been updated
to expose the new CPU features to virtual machines.

References

https://ubuntu.com/security/notices/USN-3655-2

https://ubuntu.com/security/notices/USN-3655-1

CVE-2017-12134, CVE-2017-13220, CVE-2017-13305, CVE-2017-17449,

CVE-2017-18079, CVE-2017-18203, CVE-2017-18204, CVE-2017-18208,

CVE-2017-18221, CVE-2018-3639, CVE-2018-8822, https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Variant4

Severity
critical
Lowest
Low
Medium
High
Critical

May 22, 2018

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.