Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-2267-1 July 05, 2014 linux-ec2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux-ec2: Linux kernel for EC2 Details: Andy Lutomirski discovered a flaw with the Linux kernel's ptrace syscall on x86_64 processors. An attacker could exploit this flaw to cause a denial of service (System Crash) or potential gain administrative privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-366-ec2 2.6.32-366.81 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2267-1 CVE-2014-4699 Package Information: https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-366.81 . A vulnerability in the Linux kernel may allow for system failures or unauthorized administrative access within Ubuntu's EC2 setting. Ensure you remain protected!. Linux Kernel, EC2 Security, Ubuntu Advisory, System Crash, Denial of Service. . LinuxSecurity.com Team
The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-2197-1 May 06, 2014 linux-ec2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux-ec2: Linux kernel for EC2 Details: A flaw was discovered in the Linux kernel's pseudo tty (pty) device. An unprivileged user could exploit this flaw to cause a denial of service (system crash) or potentially gain administrator privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-363-ec2 2.6.32-363.77 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2197-1 CVE-2014-0196 Package Information: https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-363.77 . A vulnerability in the Linux system kernel might enable unapproved root-level access or lead to a system crash, necessitating an immediate patch.. Ubuntu Linux Kernel, EC2 Vulnerability, System Security, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
The system's firewall could be bypassed by a remote attacker.. =========================================================================Ubuntu Security Notice USN-1664-1 December 13, 2012 linux-ec2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: The system's firewall could be bypassed by a remote attacker. Software Description: - linux-ec2: Linux kernel for EC2 Details: Zhang Zuotao discovered a bug in the Linux kernel's handling of overlapping fragments in ipv6. A remote attacker could exploit this flaw to bypass firewalls and initial new network connections that should have been blocked by the firewall. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-350-ec2 2.6.32-350.58 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1664-1 CVE-2012-4444 Package Information: https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-350.58 . Ubuntu Security Notice USN-1665-1 tackles a severe vulnerability in the ec2 kernel that permits unauthorized access through the firewall.. Ubuntu Security, Kernel Fix, EC2 Remote Access. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-1556-1 September 06, 2012 linux-ec2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux-ec2: Linux kernel for EC2 Details: Chen Haogang discovered an integer overflow that could result in memory corruption. A local unprivileged user could use this to crash the system. (CVE-2012-0044) A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation. A local, unprivileged user could use this flaw to cause a denial of service. (CVE-2012-2372) Some errors where discovered in the Linux kernel's UDF file system, which is used to mount some CD-ROMs and DVDs. An unprivileged local user could use these flaws to crash the system. (CVE-2012-3400) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-347-ec2 2.6.32-347.53 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1556-1 CVE-2012-0044, CVE-2012-2372, CVE-2012-3400 Package Information: https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-347.53 . Fedora addressed serious vulnerabilities within its core components impacting Virtual Private Servers. Upgrade immediately to safeguard your environment.. Kernel Security, Ubuntu Advisories, EC2 Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-1534-1 August 10, 2012 linux-ec2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux-ec2: Linux kernel for EC2 Details: An error was discovered in the Linux kernel's network TUN/TAP device implementation. A local user with access to the TUN/TAP interface (which is not available to unprivileged users until granted by a root user) could exploit this flaw to crash the system or potential gain administrative privileges. (CVE-2012-2136) An error was discovered in the Linux kernel's memory subsystem (hugetlb). An unprivileged local user could exploit this flaw to cause a denial of service (crash the system). (CVE-2012-2390) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-347-ec2 2.6.32-347.52 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-1534-1 CVE-2012-2136, CVE-2012-2390 Package Information: https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-347.52 . Thelatest Ubuntu Security Notice USN-1534-1 deals with critical kernel vulnerabilities on EC2 platforms, potentially impacting overall system reliability.. Kernel Security Updates, EC2 Kernel Fixes, Ubuntu System Security, Administrative Privilege Exploits. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-1388-1 March 06, 2012 linux-ec2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux-ec2: Linux kernel for EC2 Details: Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl command. A local user, or user in a VM could exploit this flaw to bypass restrictions and gain read/write access to all data on the affected block device. (CVE-2011-4127) A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual interrupt control is not available a local user could use this to cause a denial of service by starting a timer. (CVE-2011-4622) A flaw was discovered in the XFS filesystem. If a local user mounts a specially crafted XFS image it could potential execute arbitrary code on the system. (CVE-2012-0038) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-343-ec2 2.6.32-343.45 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-1388-1 CVE-2011-4127,CVE-2011-4622, CVE-2012-0038 Package Information: https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-343.45 . Ubuntu Security Notice USN-1388-1, released on March 06, 2012, addresses vulnerabilities in the Linux kernel for EC2 instances, ensuring improved security for users. Linux Kernel Security, EC2 Issues, Critical Updates. . Severity: Critical. LinuxSecurity.com Team
Dan Rosenberg discovered that multiple terminal ioctls did not correctlyinitialize structure memory. A local attacker could exploit this toread portions of kernel stack memory, leading to a loss of privacy.(CVE-2010-4076, CVE-2010-4077) [More...]. ==========================================================Ubuntu Security Notice USN-1086-1 March 08, 2011 linux-ec2 vulnerabilities CVE-2010-4076, CVE-2010-4077, CVE-2010-4158, CVE-2010-4163, CVE-2010-4175 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-314-ec2 2.6.32-314.27 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. Details follow: Dan Rosenberg discovered that multiple terminal ioctls did not correctly initialize structure memory. A local attacker could exploit this to read portions of kernel stack memory, leading to a loss of privacy. (CVE-2010-4076, CVE-2010-4077) Dan Rosenberg discovered that the socket filters did not correctly initialize structure memory. A local attacker could create malicious filters to read portions of kernel stack memory, leading to a loss of privacy. (CVE-2010-4158) Dan Rosenberg discovered that the SCSI subsystem did not correctly validate iovsegments. A local attacker with access to a SCSI device could send specially crafted requests to crash the system, leading to a denial of service. (CVE-2010-4163) Dan Rosenberg discovered that the RDS protocol did not correctly check ioctl arguments. A local attacker could exploit this to crash the system, leading to a denial of service. (CVE-2010-4175) Updated packages for Ubuntu 10.04 LTS: Source archives: Size/MD5: 9075603 3b5ed62eef9ba6d5e63ca59a308035c8 Size/MD5: 2104 71e44d7e3a2422e18abc0039f50f5002 Size/MD5: 81900940 4b1f6f6fac43a23e783079db589fc7e2 Architecture independent packages: Size/MD5: 6434392 09281aaccdce3fe2c4d70a0913ec5e49 Size/MD5: 68171196 7048f33fb28bc4a5f7634b12499b492d Size/MD5: 10046624 a385860922eb209c56960edbd4874134 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 693912 7528587b27dbfe734761131cb0efb493 Size/MD5: 20035640 bcc35c559c339452498c0b90a5e240bc i386 architecture (x86 compatible Intel/AMD): Size/MD5: 659440 a75036c9ba32e477f202074a0b02f606 Size/MD5: 19234330 cd15dca40624901035313331878edf98 . The latest Ubuntu advisory concerning EC2 kernel vulnerabilities emphasizes the urgency for prompt updates to safeguard against potential exploitation by local adversaries.. Ubuntu Kernel Security, EC2 Vulnerabilities, Memory Exploitation. . Severity: Critical. LinuxSecurity.com Team
USN-1080-1 fixed vulnerabilities in the Linux kernel. This update provides the corresponding updates for the Linux kernel for use with EC2.. ==========================================================Ubuntu Security Notice USN-1080-2 March 02, 2011 linux-ec2 vulnerabilities CVE-2010-3865, CVE-2010-3875, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-4248, CVE-2010-4343, CVE-2010-4346, CVE-2010-4526, CVE-2010-4527, CVE-2010-4649, CVE-2011-1044 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-313-ec2 2.6.32-313.26 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. Details follow: USN-1080-1 fixed vulnerabilities in the Linux kernel. This update provides the corresponding updates for the Linux kernel for use with EC2. Original advisory details: Thomas Pollet discovered that the RDS network protocol did not check certain iovec buffers. A local attacker could exploit this to crash the system or possibly execute arbitrary code as the root user. (CVE-2010-3865) Vasiliy Kulikov discovered that the Linux kernel X.25 implementation did not correctly clear kernel memory. A local attackercould exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2010-3875) Vasiliy Kulikov discovered that the Linux kernel sockets implementation did not properly initialize certain structures. A local attacker could exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2010-3876) Vasiliy Kulikov discovered that the TIPC interface did not correctly initialize certain structures. A local attacker could exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2010-3877) Nelson Elhage discovered that the Linux kernel IPv4 implementation did not properly audit certain bytecodes in netlink messages. A local attacker could exploit this to cause the kernel to hang, leading to a denial of service. (CVE-2010-3880) It was discovered that multithreaded exec did not handle CPU timers correctly. A local attacker could exploit this to crash the system, leading to a denial of service. (CVE-2010-4248) Krishna Gudipati discovered that the bfa adapter driver did not correctly initialize certain structures. A local attacker could read files in /sys to crash the system, leading to a denial of service. (CVE-2010-4343) Tavis Ormandy discovered that the install_special_mapping function could bypass the mmap_min_addr restriction. A local attacker could exploit this to mmap 4096 bytes below the mmap_min_addr area, possibly improving the chances of performing NULL pointer dereference attacks. (CVE-2010-4346) It was discovered that the ICMP stack did not correctly handle certain unreachable messages. If a remote attacker were able to acquire a socket lock, they could send specially crafted traffic that would crash the system, leading to a denial of service. (CVE-2010-4526) Dan Rosenberg discovered that the OSS subsystem did not handle name termination correctly. A local attacker could exploit this crash the system or gain root privileges. (CVE-2010-4527) Dan Carpenter discovered that theInfiniband driver did not correctly handle certain requests. A local user could exploit this to crash the system or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044) Updated packages for Ubuntu 10.04 LTS: Source archives: Size/MD5: 9006451 8cdaceb98706fe4a05ae00a5da39b42d Size/MD5: 2104 552a2f768dd9ebb658ffa7290d78618f Size/MD5: 81900940 4b1f6f6fac43a23e783079db589fc7e2 Architecture independent packages: Size/MD5: 6430856 1f1387d40cfc16fbd07b6fbb2ff911ab Size/MD5: 68190678 ce725a131a4a4450795d6b7b2ca9b17c Size/MD5: 10042660 0b79b03ef63f936c4ec70afe1fb9f175 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 691132 4cd99928f8a74ce1860b42d8f092fbd3 Size/MD5: 20005422 10cba12c56655afb94862979b703c0b0 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 656470 c34756e6bff43f09d721b0dbe63cc0a4 Size/MD5: 19230428 7dd28c8c0238f99f31bcfab4f9fc8433 . This patch focuses on addressing vulnerabilities within the Linux kernel in Ubuntu, carrying serious repercussions for security.. Linux Kernel Security, Ubuntu Kernel Update, Security Patch, EC2 Security. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.