{"cves":[{"id":"CVE-2010-4349","published":"2011-01-03T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nadmin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote\nattackers to obtain sensitive information via an invalid db_type parameter,\nwhich reveals the installation path in an error message, related to an\nunsafe call by MantisBT to a function in the ADOdb Library for PHP.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4349"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4348","published":"2011-01-03T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in\nMantisBT before 1.2.4 allows remote attackers to inject arbitrary web\nscript or HTML via the db_type parameter, related to an unsafe call by\nMantisBT to a function in the ADOdb Library for PHP.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4348"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3907","published":"2011-01-03T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in real.c in the Real demuxer plugin in VideoLAN\nVLC Media Player before 1.1.6 allow remote attackers to cause a denial of\nservice (application crash) or possibly execute arbitrary code via a zero\ni_subpackets value in a Real Media file, leading to a heap-based buffer\noverflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3907"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/690173"],"patches":{"vlc":["upstream: http://git.videolan.org/?p=vlc.git;a=commitdiff;h=6568965770f906d34d4aef83237842a5376adb55"]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.0.6-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.4-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.1.6-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-1677","published":"2011-01-03T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU\nconsumption) via start tags that are placed within other start tags, as\ndemonstrated by a dy>dy>dy>dy> sequence, a different\nvulnerability than CVE-2010-4524.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-1677"],"bugs":["http://savannah.nongnu.org/bugs/?32014"],"patches":{"mhonarc":[]},"tags":{},"packages":[{"name":"mhonarc","source":"https://ubuntu.com/security/cve?package=mhonarc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mhonarc","debian":"https://tracker.debian.org/pkg/mhonarc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.6.18-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.17","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [2.6.18-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4668","published":"2011-01-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel\nbefore 2.6.37-rc7 allows local users to cause a denial of service (panic)\nvia a zero-length I/O request in a device ioctl to a SCSI device, related\nto an unaligned map. NOTE: this vulnerability exists because of an\nincomplete fix for CVE-2010-4163.","ubuntu_description":"\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1105-1","https://ubuntu.com/security/notices/USN-1090-1","https://ubuntu.com/security/notices/USN-1086-1","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1187-1","https://ubuntu.com/security/notices/USN-1202-1","https://ubuntu.com/security/notices/USN-1204-1","https://www.cve.org/CVERecord?id=CVE-2010-4668"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=5478755616ae2ef1ce144dded589b62b2a50d575"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-29.87","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-23.74","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-30.59","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-28.49","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-11.25","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-314.27","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-610.27","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-28.50~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-216.33","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-416.33","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-57.94","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.23","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]}],"notices_ids":["USN-1090-1","USN-1202-1","USN-1105-1","USN-1204-1","USN-1187-1","USN-1086-1","USN-1093-1"],"notices":[{"id":"USN-1090-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-18T22:29:04.949180","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-30.59","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-30-generic","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-powerpc-smp","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-ia64","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-lpia","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-preempt","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-sparc64-smp","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-sparc64","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-generic-pae","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-virtual","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-server","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-powerpc","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-386","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-powerpc64-smp","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-versatile","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"}],"maverick":[{"name":"linux","version":"2.6.35-28.49","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-28-server","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-versatile","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-powerpc-smp","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-virtual","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-powerpc64-smp","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-powerpc","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-generic-pae","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-omap","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-generic","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4163","CVE-2010-4668"]},{"id":"USN-1202-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-13T20:04:34.377322","description":"\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.24","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.24"}]},"type":"USN","cves_ids":["CVE-2011-1171","CVE-2010-3297","CVE-2011-0521","CVE-2011-1163","CVE-2010-3858","CVE-2010-4163","CVE-2010-3880","CVE-2010-4073","CVE-2010-4082","CVE-2010-4162","CVE-2010-3859","CVE-2010-4075","CVE-2011-1019","CVE-2011-1170","CVE-2010-4649","CVE-2011-1090","CVE-2010-3874","CVE-2011-1082","CVE-2010-4243","CVE-2011-1012","CVE-2010-4083","CVE-2010-4655","CVE-2011-1180","CVE-2011-0695","CVE-2011-1044","CVE-2011-1173","CVE-2010-3296","CVE-2010-4169","CVE-2010-4256","CVE-2011-1172","CVE-2010-4081","CVE-2010-4242","CVE-2011-0726","CVE-2011-1080","CVE-2011-1017","CVE-2011-0463","CVE-2010-4080","CVE-2011-1079","CVE-2011-1010","CVE-2011-1013","CVE-2010-4157","CVE-2010-4565","CVE-2011-1078","CVE-2010-4077","CVE-2010-4248","CVE-2011-1169","CVE-2010-4175","CVE-2011-1020","CVE-2010-4076","CVE-2011-0712","CVE-2011-1016","CVE-2011-1160","CVE-2010-4160","CVE-2011-1093","CVE-2011-0711","CVE-2011-1577","CVE-2011-1748","CVE-2011-2492","CVE-2011-1494","CVE-2011-1478","CVE-2011-3637","CVE-2011-2918","CVE-2011-1493","CVE-2011-2022","CVE-2010-4668","CVE-2010-4656","CVE-2011-2699","CVE-2011-1746","CVE-2011-4914","CVE-2011-4913","CVE-2011-2534","CVE-2011-1745","CVE-2011-1770","CVE-2011-1833","CVE-2011-1495","CVE-2011-1598","CVE-2011-2484","CVE-2011-1593","CVE-2011-1182"]},{"id":"USN-1105-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-04-05T18:47:41.036711","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-29.88","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-29-sparc64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-rt","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-386","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-itanium","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa32","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-openvz","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-generic","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-xen","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-server","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpia","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-virtual","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-mckinley","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-sparc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpiacompat","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4242","CVE-2010-4258","CVE-2010-4346","CVE-2010-4668"]},{"id":"USN-1204-1","title":"Linux kernel (i.MX51) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-09-13T20:11:32.087550","description":"\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlex Shi and Eric Dumazet discovered that the network stack did not\ncorrectly handle packet backlogs. A remote attacker could exploit this by\nsending a large amount of network traffic to cause the system to run out of\nmemory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-610.28","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-610-imx51","version":"2.6.31-610.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-610.28"}]},"type":"USN","cves_ids":["CVE-2011-2918","CVE-2011-3637","CVE-2011-4913","CVE-2011-4914","CVE-2010-3859","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4251","CVE-2010-4526","CVE-2010-4649","CVE-2010-4668","CVE-2010-4805","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1020","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1478","CVE-2011-1493","CVE-2011-1577","CVE-2011-1598","CVE-2011-1770","CVE-2011-1833","CVE-2011-2484","CVE-2011-2492","CVE-2011-2534","CVE-2011-2699"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1086-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Multiple kernel vulnerabilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-08T23:44:41.516167","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-314.27","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-314-ec2","version":"2.6.32-314.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-314.27"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4158","CVE-2010-4163","CVE-2010-4668"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-4164","published":"2011-01-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer underflows in the x25_parse_facilities function in\nnet/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote\nattackers to cause a denial of service (system crash) via malformed X.25\n(1) X25_FAC_CLASS_A, (2) X25_FAC_CLASS_B, (3) X25_FAC_CLASS_C, or (4)\nX25_FAC_CLASS_D facility data, a different vulnerability than\nCVE-2010-3873.","ubuntu_description":"\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1105-1","https://ubuntu.com/security/notices/USN-1119-1","https://ubuntu.com/security/notices/USN-1111-1","https://ubuntu.com/security/notices/USN-1083-1","https://ubuntu.com/security/notices/USN-1054-1","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1164-1","https://ubuntu.com/security/notices/USN-1167-1","https://www.cve.org/CVERecord?id=CVE-2010-4164"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=5ef41308f94dcbb3b7afc56cdef1c2ba53fa5d2f"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-29.88","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-28.52","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-25.43","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-5.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-312.24","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-609.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-214.30","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-414.30","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-57.95","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1164-1","USN-1105-1","USN-1083-1","USN-1054-1","USN-1111-1","USN-1119-1","USN-1093-1"],"notices":[{"id":"USN-1164-1","title":"Linux kernel vulnerabilities (i.MX51)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-06T13:09:52.089799","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-609.26","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-609-imx51","version":"2.6.31-609.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-609.26"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4342","CVE-2010-3877","CVE-2010-3876","CVE-2010-3875","CVE-2010-4258","CVE-2010-4164","CVE-2010-3873","CVE-2010-4346","CVE-2010-4527","CVE-2010-3865","CVE-2010-3874","CVE-2010-3880","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4248","CVE-2010-4565","CVE-2010-4655","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-1017","CVE-2011-1182","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022"]},{"id":"USN-1105-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-04-05T18:47:41.036711","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-29.88","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-29-sparc64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-rt","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-386","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-itanium","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa32","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-openvz","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-generic","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-xen","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-server","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpia","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-virtual","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-mckinley","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-sparc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpiacompat","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4242","CVE-2010-4258","CVE-2010-4346","CVE-2010-4668"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1054-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerablilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-02-01T23:25:34.849006","description":"\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-312.24","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-28.55","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-28-preempt","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-386","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc64-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-sparc64-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-lpia","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-ia64","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-server","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-versatile","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-312-ec2","version":"2.6.32-312.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-312.24"},{"name":"linux-image-2.6.32-28-sparc64","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-generic","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-virtual","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-generic-pae","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"}],"maverick":[{"name":"linux","version":"2.6.35-25.44","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-omap","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc-smp","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc64-smp","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-versatile","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"}]},"type":"USN","cves_ids":["CVE-2010-4079","CVE-2010-3881","CVE-2010-0435","CVE-2010-3859","CVE-2010-3873","CVE-2010-3874","CVE-2010-4073","CVE-2010-4083","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258"]},{"id":"USN-1111-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-05-05T21:15:33.314123","description":"Dan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-57.97","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-57-itanium","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa64-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-k8","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa32","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-386","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-powerpc","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-server-bigiron","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-server","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-k7","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-server","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-powerpc-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-686","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa32-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-generic","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-itanium-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa64","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-powerpc64-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-sparc64","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-mckinley","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-mckinley-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-xeon","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-sparc64-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"}]},"type":"USN","cves_ids":["CVE-2010-4164","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4527","CVE-2010-4529","CVE-2011-0521","CVE-2011-0695","CVE-2011-1017"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-4163","published":"2011-01-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel\nbefore 2.6.36.2 allows local users to cause a denial of service (panic) via\na zero-length I/O request in a device ioctl to a SCSI device.","ubuntu_description":"\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1086-1","https://ubuntu.com/security/notices/USN-1089-1","https://ubuntu.com/security/notices/USN-1090-1","https://ubuntu.com/security/notices/USN-1092-1","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1105-1","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1187-1","https://ubuntu.com/security/notices/USN-1202-1","https://ubuntu.com/security/notices/USN-1204-1","https://www.cve.org/CVERecord?id=CVE-2010-4163"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9284bcf4e335e5f18a8bc7b26461c33ab60d0689","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5478755616ae2ef1ce144dded589b62b2a50d575"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"karmic","status":"released","description":"2.6.31-23.74","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-29.87","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-30.59","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-28.49","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-11.25","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-308.28","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-314.27","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-610.27","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-28.50~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-216.33","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-416.33","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-57.94","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.23","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc7","component":null,"pocket":"security"}]}],"notices_ids":["USN-1092-1","USN-1090-1","USN-1089-1","USN-1202-1","USN-1105-1","USN-1204-1","USN-1187-1","USN-1086-1","USN-1093-1"],"notices":[{"id":"USN-1092-1","title":"Linux Kernel vulnerabilities","summary":"A local attacker could exploit this to run programs with admininstrator\nprivileges.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-25T15:39:04.386710","description":"Dan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-57.94","description":"ACPI support modules (udeb)","is_source":true},{"name":"linux-image-2.6.15-57-itanium","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa64-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-k8","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa32","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-386","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-powerpc","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-server-bigiron","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-server","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-k7","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-server","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-powerpc-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-686","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa32-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-generic","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-itanium-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa64","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-powerpc64-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-sparc64","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-mckinley","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-mckinley-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-xeon","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-sparc64-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4077","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4242"]},{"id":"USN-1090-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-18T22:29:04.949180","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-30.59","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-30-generic","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-powerpc-smp","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-ia64","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-lpia","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-preempt","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-sparc64-smp","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-sparc64","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-generic-pae","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-virtual","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-server","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-powerpc","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-386","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-powerpc64-smp","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"},{"name":"linux-image-2.6.32-30-versatile","version":"2.6.32-30.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-30.59"}],"maverick":[{"name":"linux","version":"2.6.35-28.49","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-28-server","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-versatile","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-powerpc-smp","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-virtual","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-powerpc64-smp","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-powerpc","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-generic-pae","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-omap","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"},{"name":"linux-image-2.6.35-28-generic","version":"2.6.35-28.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-28.49"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4163","CVE-2010-4668"]},{"id":"USN-1089-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-18T21:48:41.874444","description":"Dan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if\na write operation was available. If the mmap_min-addr sysctl was changed\nfrom the Ubuntu default to a value of 0, a local attacker could exploit\nthis flaw to gain root privileges. (CVE-2010-4242)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-ec2","version":"2.6.31-308.28","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-23.74","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-23-generic","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-sparc64-smp","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-powerpc-smp","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-powerpc64-smp","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-308-ec2","version":"2.6.31-308.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-308.28"},{"name":"linux-image-2.6.31-23-virtual","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-generic-pae","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-lpia","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-powerpc","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-sparc64","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-server","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-ia64","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-386","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4175","CVE-2010-4242"]},{"id":"USN-1202-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-13T20:04:34.377322","description":"\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.24","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.24"}]},"type":"USN","cves_ids":["CVE-2011-1171","CVE-2010-3297","CVE-2011-0521","CVE-2011-1163","CVE-2010-3858","CVE-2010-4163","CVE-2010-3880","CVE-2010-4073","CVE-2010-4082","CVE-2010-4162","CVE-2010-3859","CVE-2010-4075","CVE-2011-1019","CVE-2011-1170","CVE-2010-4649","CVE-2011-1090","CVE-2010-3874","CVE-2011-1082","CVE-2010-4243","CVE-2011-1012","CVE-2010-4083","CVE-2010-4655","CVE-2011-1180","CVE-2011-0695","CVE-2011-1044","CVE-2011-1173","CVE-2010-3296","CVE-2010-4169","CVE-2010-4256","CVE-2011-1172","CVE-2010-4081","CVE-2010-4242","CVE-2011-0726","CVE-2011-1080","CVE-2011-1017","CVE-2011-0463","CVE-2010-4080","CVE-2011-1079","CVE-2011-1010","CVE-2011-1013","CVE-2010-4157","CVE-2010-4565","CVE-2011-1078","CVE-2010-4077","CVE-2010-4248","CVE-2011-1169","CVE-2010-4175","CVE-2011-1020","CVE-2010-4076","CVE-2011-0712","CVE-2011-1016","CVE-2011-1160","CVE-2010-4160","CVE-2011-1093","CVE-2011-0711","CVE-2011-1577","CVE-2011-1748","CVE-2011-2492","CVE-2011-1494","CVE-2011-1478","CVE-2011-3637","CVE-2011-2918","CVE-2011-1493","CVE-2011-2022","CVE-2010-4668","CVE-2010-4656","CVE-2011-2699","CVE-2011-1746","CVE-2011-4914","CVE-2011-4913","CVE-2011-2534","CVE-2011-1745","CVE-2011-1770","CVE-2011-1833","CVE-2011-1495","CVE-2011-1598","CVE-2011-2484","CVE-2011-1593","CVE-2011-1182"]},{"id":"USN-1105-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-04-05T18:47:41.036711","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-29.88","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-29-sparc64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-rt","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-386","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-itanium","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa32","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-openvz","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-generic","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-xen","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-server","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpia","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-virtual","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-mckinley","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-sparc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpiacompat","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4242","CVE-2010-4258","CVE-2010-4346","CVE-2010-4668"]},{"id":"USN-1204-1","title":"Linux kernel (i.MX51) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-09-13T20:11:32.087550","description":"\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlex Shi and Eric Dumazet discovered that the network stack did not\ncorrectly handle packet backlogs. A remote attacker could exploit this by\nsending a large amount of network traffic to cause the system to run out of\nmemory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-610.28","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-610-imx51","version":"2.6.31-610.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-610.28"}]},"type":"USN","cves_ids":["CVE-2011-2918","CVE-2011-3637","CVE-2011-4913","CVE-2011-4914","CVE-2010-3859","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4251","CVE-2010-4526","CVE-2010-4649","CVE-2010-4668","CVE-2010-4805","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1020","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1478","CVE-2011-1493","CVE-2011-1577","CVE-2011-1598","CVE-2011-1770","CVE-2011-1833","CVE-2011-2484","CVE-2011-2492","CVE-2011-2534","CVE-2011-2699"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1086-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Multiple kernel vulnerabilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-08T23:44:41.516167","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-314.27","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-314-ec2","version":"2.6.32-314.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-314.27"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4158","CVE-2010-4163","CVE-2010-4668"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-4162","published":"2011-01-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2\nallow local users to cause a denial of service (system crash) via a crafted\ndevice ioctl to a SCSI device.","ubuntu_description":"\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1089-1","https://ubuntu.com/security/notices/USN-1092-1","https://ubuntu.com/security/notices/USN-1105-1","https://ubuntu.com/security/notices/USN-1083-1","https://ubuntu.com/security/notices/USN-1054-1","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1202-1","https://ubuntu.com/security/notices/USN-1204-1","https://www.cve.org/CVERecord?id=CVE-2010-4162"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=cb4644cac4a2797afc847e6c92736664d4b0ea34"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-29.87","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-23.74","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-28.52","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-25.43","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-5.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-308.28","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-312.24","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-610.27","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-214.30","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-414.30","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-57.94","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.23","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1092-1","USN-1089-1","USN-1202-1","USN-1105-1","USN-1083-1","USN-1054-1","USN-1204-1","USN-1093-1"],"notices":[{"id":"USN-1092-1","title":"Linux Kernel vulnerabilities","summary":"A local attacker could exploit this to run programs with admininstrator\nprivileges.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-25T15:39:04.386710","description":"Dan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-57.94","description":"ACPI support modules (udeb)","is_source":true},{"name":"linux-image-2.6.15-57-itanium","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa64-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-k8","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa32","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-386","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-powerpc","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-server-bigiron","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-server","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-k7","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-server","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-powerpc-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-686","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa32-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-generic","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-itanium-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-hppa64","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-powerpc64-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-sparc64","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-mckinley","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-mckinley-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-amd64-xeon","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"},{"name":"linux-image-2.6.15-57-sparc64-smp","version":"2.6.15-57.94","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.94"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4077","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4242"]},{"id":"USN-1089-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-18T21:48:41.874444","description":"Dan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if\na write operation was available. If the mmap_min-addr sysctl was changed\nfrom the Ubuntu default to a value of 0, a local attacker could exploit\nthis flaw to gain root privileges. (CVE-2010-4242)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-ec2","version":"2.6.31-308.28","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-23.74","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-23-generic","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-sparc64-smp","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-powerpc-smp","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-powerpc64-smp","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-308-ec2","version":"2.6.31-308.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-308.28"},{"name":"linux-image-2.6.31-23-virtual","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-generic-pae","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-lpia","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-powerpc","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-sparc64","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-server","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-ia64","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"},{"name":"linux-image-2.6.31-23-386","version":"2.6.31-23.74","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-23.74"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4175","CVE-2010-4242"]},{"id":"USN-1202-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-13T20:04:34.377322","description":"\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.24","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.24"}]},"type":"USN","cves_ids":["CVE-2011-1171","CVE-2010-3297","CVE-2011-0521","CVE-2011-1163","CVE-2010-3858","CVE-2010-4163","CVE-2010-3880","CVE-2010-4073","CVE-2010-4082","CVE-2010-4162","CVE-2010-3859","CVE-2010-4075","CVE-2011-1019","CVE-2011-1170","CVE-2010-4649","CVE-2011-1090","CVE-2010-3874","CVE-2011-1082","CVE-2010-4243","CVE-2011-1012","CVE-2010-4083","CVE-2010-4655","CVE-2011-1180","CVE-2011-0695","CVE-2011-1044","CVE-2011-1173","CVE-2010-3296","CVE-2010-4169","CVE-2010-4256","CVE-2011-1172","CVE-2010-4081","CVE-2010-4242","CVE-2011-0726","CVE-2011-1080","CVE-2011-1017","CVE-2011-0463","CVE-2010-4080","CVE-2011-1079","CVE-2011-1010","CVE-2011-1013","CVE-2010-4157","CVE-2010-4565","CVE-2011-1078","CVE-2010-4077","CVE-2010-4248","CVE-2011-1169","CVE-2010-4175","CVE-2011-1020","CVE-2010-4076","CVE-2011-0712","CVE-2011-1016","CVE-2011-1160","CVE-2010-4160","CVE-2011-1093","CVE-2011-0711","CVE-2011-1577","CVE-2011-1748","CVE-2011-2492","CVE-2011-1494","CVE-2011-1478","CVE-2011-3637","CVE-2011-2918","CVE-2011-1493","CVE-2011-2022","CVE-2010-4668","CVE-2010-4656","CVE-2011-2699","CVE-2011-1746","CVE-2011-4914","CVE-2011-4913","CVE-2011-2534","CVE-2011-1745","CVE-2011-1770","CVE-2011-1833","CVE-2011-1495","CVE-2011-1598","CVE-2011-2484","CVE-2011-1593","CVE-2011-1182"]},{"id":"USN-1105-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-04-05T18:47:41.036711","description":"\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-29.88","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-29-sparc64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-rt","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-386","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-itanium","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa32","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-openvz","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-generic","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-xen","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-hppa64","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-server","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-powerpc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpia","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-virtual","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-mckinley","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-sparc64-smp","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"},{"name":"linux-image-2.6.24-29-lpiacompat","version":"2.6.24-29.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.88"}]},"type":"USN","cves_ids":["CVE-2010-4075","CVE-2010-4158","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4242","CVE-2010-4258","CVE-2010-4346","CVE-2010-4668"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1054-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerablilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-02-01T23:25:34.849006","description":"\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-312.24","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-28.55","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-28-preempt","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-386","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc64-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-sparc64-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-lpia","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-ia64","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-server","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-versatile","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-312-ec2","version":"2.6.32-312.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-312.24"},{"name":"linux-image-2.6.32-28-sparc64","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-generic","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-virtual","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-generic-pae","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"}],"maverick":[{"name":"linux","version":"2.6.35-25.44","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-omap","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc-smp","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc64-smp","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-versatile","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"}]},"type":"USN","cves_ids":["CVE-2010-4079","CVE-2010-3881","CVE-2010-0435","CVE-2010-3859","CVE-2010-3873","CVE-2010-3874","CVE-2010-4073","CVE-2010-4083","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258"]},{"id":"USN-1204-1","title":"Linux kernel (i.MX51) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-09-13T20:11:32.087550","description":"\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlex Shi and Eric Dumazet discovered that the network stack did not\ncorrectly handle packet backlogs. A remote attacker could exploit this by\nsending a large amount of network traffic to cause the system to run out of\nmemory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-610.28","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-610-imx51","version":"2.6.31-610.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-610.28"}]},"type":"USN","cves_ids":["CVE-2011-2918","CVE-2011-3637","CVE-2011-4913","CVE-2011-4914","CVE-2010-3859","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4251","CVE-2010-4526","CVE-2010-4649","CVE-2010-4668","CVE-2010-4805","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1020","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1478","CVE-2011-1493","CVE-2011-1577","CVE-2011-1598","CVE-2011-1770","CVE-2011-1833","CVE-2011-2484","CVE-2011-2492","CVE-2011-2534","CVE-2011-2699"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-3877","published":"2011-01-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe get_name function in net/tipc/socket.c in the Linux kernel before\n2.6.37-rc2 does not initialize a certain structure, which allows local\nusers to obtain potentially sensitive information from kernel stack memory\nby reading a copy of this structure.","ubuntu_description":"\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1072-1","https://ubuntu.com/security/notices/USN-1073-1","https://ubuntu.com/security/notices/USN-1080-1","https://ubuntu.com/security/notices/USN-1081-1","https://ubuntu.com/security/notices/USN-1080-2","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1119-1","https://ubuntu.com/security/notices/USN-1164-1","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1187-1","https://www.cve.org/CVERecord?id=CVE-2010-3877"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=88f8a5e3e7defccd3925cabb1ee4d3994e5cdb52"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.86","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.73","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-29.58","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-27.47","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-5.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.27","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-313.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-609.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-28.50~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-215.31","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-415.32","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1073-1","USN-1080-1","USN-1080-2","USN-1072-1","USN-1164-1","USN-1081-1","USN-1187-1","USN-1119-1","USN-1093-1"],"notices":[{"id":"USN-1073-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:15:38.718890","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nThomas Pollet discovered that the RDS network protocol did not\ncheck certain iovec buffers. A local attacker could exploit this\nto crash the system or possibly execute arbitrary code as the root\nuser. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as\nthe root user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly\nclear kernel memory. A local attacker could exploit this to read kernel\nstack memory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-ec2","version":"2.6.31-307.27","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.27"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"}]},"type":"USN","cves_ids":["CVE-2010-4078","CVE-2010-4074","CVE-2010-3448","CVE-2010-0435","CVE-2010-3698","CVE-2010-3859","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4073","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4165","CVE-2010-4169","CVE-2010-4248","CVE-2010-4249"]},{"id":"USN-1080-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-01T22:32:56.699741","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-29.58","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-29-versatile","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-sparc64-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-lpia","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-preempt","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-generic-pae","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-virtual","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-386","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-generic","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-ia64","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-server","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc64-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-sparc64","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"}]},"type":"USN","cves_ids":["CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4248","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044"]},{"id":"USN-1080-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-02T23:07:39.266512","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-313.26","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-313-ec2","version":"2.6.32-313.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-313.26"}]},"type":"USN","cves_ids":["CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4248","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044"]},{"id":"USN-1072-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T22:59:02.971277","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nDan Jacobson discovered that ThinkPad video output was not correctly\naccess controlled. A local attacker could exploit this to hang the system,\nleading to a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-3698)\n\nIt was discovered that Xen did not correctly clean up threads. A local\nattacker in a guest system could exploit this to exhaust host system\nresources, leading to a denial of serivce. (CVE-2010-3699)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4248)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-28.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"}]},"type":"USN","cves_ids":["CVE-2010-3699","CVE-2010-0435","CVE-2010-2943","CVE-2010-3296","CVE-2010-3297","CVE-2010-3448","CVE-2010-3698","CVE-2010-3858","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4072","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4248"]},{"id":"USN-1164-1","title":"Linux kernel vulnerabilities (i.MX51)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-06T13:09:52.089799","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-609.26","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-609-imx51","version":"2.6.31-609.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-609.26"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4342","CVE-2010-3877","CVE-2010-3876","CVE-2010-3875","CVE-2010-4258","CVE-2010-4164","CVE-2010-3873","CVE-2010-4346","CVE-2010-4527","CVE-2010-3865","CVE-2010-3874","CVE-2010-3880","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4248","CVE-2010-4565","CVE-2010-4655","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-1017","CVE-2011-1182","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022"]},{"id":"USN-1081-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-02T01:20:00.841133","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-27.48","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-27-generic-pae","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-server","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-generic","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-omap","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-versatile","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc64-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-virtual","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4079","CVE-2010-4083","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044","CVE-2011-4621"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-3876","published":"2011-01-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnet/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not\nproperly initialize certain structure members, which allows local users to\nobtain potentially sensitive information from kernel stack memory by\nleveraging the CAP_NET_RAW capability to read copies of the applicable\nstructures.","ubuntu_description":"\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1071-1","https://ubuntu.com/security/notices/USN-1072-1","https://ubuntu.com/security/notices/USN-1073-1","https://ubuntu.com/security/notices/USN-1080-1","https://ubuntu.com/security/notices/USN-1081-1","https://ubuntu.com/security/notices/USN-1080-2","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1119-1","https://ubuntu.com/security/notices/USN-1164-1","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1187-1","https://www.cve.org/CVERecord?id=CVE-2010-3876"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=67286640f638f5ad41a946b9a3dc75327950248f"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.86","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.73","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-29.58","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-27.47","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-5.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.27","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-313.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-609.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-28.50~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-215.31","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-415.32","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.93","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1073-1","USN-1080-1","USN-1080-2","USN-1072-1","USN-1164-1","USN-1081-1","USN-1187-1","USN-1119-1","USN-1071-1","USN-1093-1"],"notices":[{"id":"USN-1073-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:15:38.718890","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nThomas Pollet discovered that the RDS network protocol did not\ncheck certain iovec buffers. A local attacker could exploit this\nto crash the system or possibly execute arbitrary code as the root\nuser. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as\nthe root user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly\nclear kernel memory. A local attacker could exploit this to read kernel\nstack memory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-ec2","version":"2.6.31-307.27","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.27"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"}]},"type":"USN","cves_ids":["CVE-2010-4078","CVE-2010-4074","CVE-2010-3448","CVE-2010-0435","CVE-2010-3698","CVE-2010-3859","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4073","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4165","CVE-2010-4169","CVE-2010-4248","CVE-2010-4249"]},{"id":"USN-1080-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-01T22:32:56.699741","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-29.58","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-29-versatile","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-sparc64-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-lpia","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-preempt","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-generic-pae","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-virtual","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-386","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-generic","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-ia64","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-server","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc64-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-sparc64","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"}]},"type":"USN","cves_ids":["CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4248","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044"]},{"id":"USN-1080-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-02T23:07:39.266512","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-313.26","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-313-ec2","version":"2.6.32-313.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-313.26"}]},"type":"USN","cves_ids":["CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4248","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044"]},{"id":"USN-1072-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T22:59:02.971277","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nDan Jacobson discovered that ThinkPad video output was not correctly\naccess controlled. A local attacker could exploit this to hang the system,\nleading to a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-3698)\n\nIt was discovered that Xen did not correctly clean up threads. A local\nattacker in a guest system could exploit this to exhaust host system\nresources, leading to a denial of serivce. (CVE-2010-3699)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4248)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-28.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"}]},"type":"USN","cves_ids":["CVE-2010-3699","CVE-2010-0435","CVE-2010-2943","CVE-2010-3296","CVE-2010-3297","CVE-2010-3448","CVE-2010-3698","CVE-2010-3858","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4072","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4248"]},{"id":"USN-1164-1","title":"Linux kernel vulnerabilities (i.MX51)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-06T13:09:52.089799","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-609.26","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-609-imx51","version":"2.6.31-609.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-609.26"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4342","CVE-2010-3877","CVE-2010-3876","CVE-2010-3875","CVE-2010-4258","CVE-2010-4164","CVE-2010-3873","CVE-2010-4346","CVE-2010-4527","CVE-2010-3865","CVE-2010-3874","CVE-2010-3880","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4248","CVE-2010-4565","CVE-2010-4655","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-1017","CVE-2011-1182","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022"]},{"id":"USN-1081-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-02T01:20:00.841133","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-27.48","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-27-generic-pae","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-server","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-generic","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-omap","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-versatile","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc64-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-virtual","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4079","CVE-2010-4083","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044","CVE-2011-4621"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1071-1","title":"Linux kernel vulnerabilities","summary":"","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T20:26:05.965074","description":"Tavis Ormandy discovered that the Linux kernel did not properly implement\nexception fixup. A local attacker could exploit this to crash the kernel,\nleading to a denial of service. (CVE-2010-3086)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation\ndid not properly initialize certain structures. A local attacker could\nexploit this to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.93","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"}]},"type":"USN","cves_ids":["CVE-2010-3086","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3880","CVE-2010-4078","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-3875","published":"2011-01-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before\n2.6.37-rc2 does not initialize a certain structure, which allows local\nusers to obtain potentially sensitive information from kernel stack memory\nby reading a copy of this structure.","ubuntu_description":"\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1071-1","https://ubuntu.com/security/notices/USN-1072-1","https://ubuntu.com/security/notices/USN-1073-1","https://ubuntu.com/security/notices/USN-1080-1","https://ubuntu.com/security/notices/USN-1081-1","https://ubuntu.com/security/notices/USN-1080-2","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1119-1","https://ubuntu.com/security/notices/USN-1164-1","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1187-1","https://www.cve.org/CVERecord?id=CVE-2010-3875"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=fe10ae53384e48c51996941b7720ee16995cbcb7"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.86","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.73","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-29.58","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-27.47","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-5.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.27","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-313.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-609.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-28.50~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-215.31","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-415.32","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.93","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1073-1","USN-1080-1","USN-1080-2","USN-1072-1","USN-1164-1","USN-1081-1","USN-1187-1","USN-1119-1","USN-1071-1","USN-1093-1"],"notices":[{"id":"USN-1073-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:15:38.718890","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nThomas Pollet discovered that the RDS network protocol did not\ncheck certain iovec buffers. A local attacker could exploit this\nto crash the system or possibly execute arbitrary code as the root\nuser. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as\nthe root user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly\nclear kernel memory. A local attacker could exploit this to read kernel\nstack memory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-ec2","version":"2.6.31-307.27","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.27"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"}]},"type":"USN","cves_ids":["CVE-2010-4078","CVE-2010-4074","CVE-2010-3448","CVE-2010-0435","CVE-2010-3698","CVE-2010-3859","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4073","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4165","CVE-2010-4169","CVE-2010-4248","CVE-2010-4249"]},{"id":"USN-1080-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-01T22:32:56.699741","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-29.58","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-29-versatile","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-sparc64-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-lpia","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-preempt","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-generic-pae","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-virtual","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-386","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-generic","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-ia64","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-server","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc64-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-powerpc-smp","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"},{"name":"linux-image-2.6.32-29-sparc64","version":"2.6.32-29.58","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-29.58"}]},"type":"USN","cves_ids":["CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4248","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044"]},{"id":"USN-1080-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-02T23:07:39.266512","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-313.26","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-313-ec2","version":"2.6.32-313.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-313.26"}]},"type":"USN","cves_ids":["CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4248","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044"]},{"id":"USN-1072-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T22:59:02.971277","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nDan Jacobson discovered that ThinkPad video output was not correctly\naccess controlled. A local attacker could exploit this to hang the system,\nleading to a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-3698)\n\nIt was discovered that Xen did not correctly clean up threads. A local\nattacker in a guest system could exploit this to exhaust host system\nresources, leading to a denial of serivce. (CVE-2010-3699)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4248)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-28.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"}]},"type":"USN","cves_ids":["CVE-2010-3699","CVE-2010-0435","CVE-2010-2943","CVE-2010-3296","CVE-2010-3297","CVE-2010-3448","CVE-2010-3698","CVE-2010-3858","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4072","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4248"]},{"id":"USN-1164-1","title":"Linux kernel vulnerabilities (i.MX51)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-06T13:09:52.089799","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-609.26","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-609-imx51","version":"2.6.31-609.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-609.26"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4342","CVE-2010-3877","CVE-2010-3876","CVE-2010-3875","CVE-2010-4258","CVE-2010-4164","CVE-2010-3873","CVE-2010-4346","CVE-2010-4527","CVE-2010-3865","CVE-2010-3874","CVE-2010-3880","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4248","CVE-2010-4565","CVE-2010-4655","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-1017","CVE-2011-1182","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022"]},{"id":"USN-1081-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-02T01:20:00.841133","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-27.48","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-27-generic-pae","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-server","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-generic","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-omap","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-versatile","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc64-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-virtual","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4079","CVE-2010-4083","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044","CVE-2011-4621"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1071-1","title":"Linux kernel vulnerabilities","summary":"","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T20:26:05.965074","description":"Tavis Ormandy discovered that the Linux kernel did not properly implement\nexception fixup. A local attacker could exploit this to crash the kernel,\nleading to a denial of service. (CVE-2010-3086)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation\ndid not properly initialize certain structures. A local attacker could\nexploit this to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.93","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"}]},"type":"USN","cves_ids":["CVE-2010-3086","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3880","CVE-2010-4078","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-3873","published":"2011-01-03T00:00:00","updated_at":"2026-07-04T07:33:39.706909+00:00","description":"\nThe X.25 implementation in the Linux kernel before 2.6.36.2 does not\nproperly parse facilities, which allows remote attackers to cause a denial\nof service (heap memory corruption and panic) or possibly have unspecified\nother impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE\ndata, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different\nvulnerability than CVE-2010-4164.","ubuntu_description":"\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service.","notes":[{"author":"kees","note":"net: ax25: fix information leak to userland harder, CVE-2010-3875 We\ntook the additional step of fixing the original patch since it allowed an\nSKB leak."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1071-1","https://ubuntu.com/security/notices/USN-1072-1","https://ubuntu.com/security/notices/USN-1073-1","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1119-1","https://ubuntu.com/security/notices/USN-1164-1","https://ubuntu.com/security/notices/USN-1054-1","https://ubuntu.com/security/notices/USN-1244-1","https://www.cve.org/CVERecord?id=CVE-2010-3873"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["break-fix: - a6331d6f9a4298173b413cf99a40cc86a9d92c37"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.86","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.73","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-28.52","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-25.43","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-5.13","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.39-0.0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.27","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-312.24","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-609.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-32.68~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-214.30","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-414.30","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.93","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.26","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1073-1","USN-1072-1","USN-1164-1","USN-1054-1","USN-1244-1","USN-1071-1","USN-1093-1"],"notices":[{"id":"USN-1073-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:15:38.718890","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nThomas Pollet discovered that the RDS network protocol did not\ncheck certain iovec buffers. A local attacker could exploit this\nto crash the system or possibly execute arbitrary code as the root\nuser. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as\nthe root user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly\nclear kernel memory. A local attacker could exploit this to read kernel\nstack memory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-ec2","version":"2.6.31-307.27","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.27"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"}]},"type":"USN","cves_ids":["CVE-2010-4078","CVE-2010-4074","CVE-2010-3448","CVE-2010-0435","CVE-2010-3698","CVE-2010-3859","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4073","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4165","CVE-2010-4169","CVE-2010-4248","CVE-2010-4249"]},{"id":"USN-1072-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T22:59:02.971277","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nDan Jacobson discovered that ThinkPad video output was not correctly\naccess controlled. A local attacker could exploit this to hang the system,\nleading to a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-3698)\n\nIt was discovered that Xen did not correctly clean up threads. A local\nattacker in a guest system could exploit this to exhaust host system\nresources, leading to a denial of serivce. (CVE-2010-3699)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4248)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-28.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"}]},"type":"USN","cves_ids":["CVE-2010-3699","CVE-2010-0435","CVE-2010-2943","CVE-2010-3296","CVE-2010-3297","CVE-2010-3448","CVE-2010-3698","CVE-2010-3858","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4072","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4248"]},{"id":"USN-1164-1","title":"Linux kernel vulnerabilities (i.MX51)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-06T13:09:52.089799","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-609.26","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-609-imx51","version":"2.6.31-609.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-609.26"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4342","CVE-2010-3877","CVE-2010-3876","CVE-2010-3875","CVE-2010-4258","CVE-2010-4164","CVE-2010-3873","CVE-2010-4346","CVE-2010-4527","CVE-2010-3865","CVE-2010-3874","CVE-2010-3880","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4248","CVE-2010-4565","CVE-2010-4655","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-1017","CVE-2011-1182","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022"]},{"id":"USN-1054-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerablilities.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-02-01T23:25:34.849006","description":"\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-312.24","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-28.55","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-28-preempt","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-386","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc64-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-sparc64-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-lpia","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-ia64","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-server","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-versatile","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-powerpc-smp","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-312-ec2","version":"2.6.32-312.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-312.24"},{"name":"linux-image-2.6.32-28-sparc64","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-generic","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-virtual","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"},{"name":"linux-image-2.6.32-28-generic-pae","version":"2.6.32-28.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-28.55"}],"maverick":[{"name":"linux","version":"2.6.35-25.44","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-omap","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc-smp","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-powerpc64-smp","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-versatile","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-25.44"}]},"type":"USN","cves_ids":["CVE-2010-4079","CVE-2010-3881","CVE-2010-0435","CVE-2010-3859","CVE-2010-3873","CVE-2010-3874","CVE-2010-4073","CVE-2010-4083","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258"]},{"id":"USN-1244-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-10-25T13:06:26.366639","description":"Dan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nAndrea Righi discovered a race condition in the KSM memory merging support.\nIf KSM was being used, a local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-2183)\n\nVasily Averin discovered that the NFS Lock Manager (NLM) incorrectly\nhandled unlock requests. A local attacker could exploit this to cause a\ndenial of service. (CVE-2011-2491)\n\nVasiliy Kulikov discovered that taskstats did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2494)\n\nVasiliy Kulikov discovered that /proc/PID/io did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2495)\n\nIt was discovered that the wireless stack incorrectly verified SSID\nlengths. A local attacker could exploit this to cause a denial of service\nor gain root privileges. (CVE-2011-2517)\n\nIt was discovered that the EXT4 filesystem contained multiple off-by-one\nflaws. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2011-2695)\n\nChristian Ohm discovered that the perf command looks for configuration\nfiles in the current directory. If a privileged user were tricked into\nrunning perf in a directory containing a malicious configuration file, an\nattacker could run arbitrary commands and possibly gain privileges.\n(CVE-2011-2905)\n\nVasiliy Kulikov discovered that the Comedi driver did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-2909)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.26","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.26"}]},"type":"USN","cves_ids":["CVE-2010-3873","CVE-2011-2183","CVE-2011-2491","CVE-2011-2494","CVE-2011-2495","CVE-2011-2517","CVE-2011-2695","CVE-2011-2905","CVE-2011-2909","CVE-2011-3363"]},{"id":"USN-1071-1","title":"Linux kernel vulnerabilities","summary":"","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T20:26:05.965074","description":"Tavis Ormandy discovered that the Linux kernel did not properly implement\nexception fixup. A local attacker could exploit this to crash the kernel,\nleading to a denial of service. (CVE-2010-3086)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation\ndid not properly initialize certain structures. A local attacker could\nexploit this to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.93","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.93","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.93"}]},"type":"USN","cves_ids":["CVE-2010-3086","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3880","CVE-2010-4078","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-3448","published":"2011-01-03T00:00:00","updated_at":"2026-07-04T07:32:59.792963+00:00","description":"\ndrivers/platform/x86/thinkpad_acpi.c in the Linux kernel before 2.6.34 on\nThinkPad devices, when the X.Org X server is used, does not properly\nrestrict access to the video output control state, which allows local users\nto cause a denial of service (system hang) via a (1) read or (2) write\noperation.","ubuntu_description":"\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service.","notes":[{"author":"rtg","note":"Upstream b525c06cdbd8a3963f0173ccd23f9147d4c384b5 fixes this\nissue. It has propagated to stable kernels down to 2.6.32.y"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1072-1","https://ubuntu.com/security/notices/USN-1073-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1093-1","https://www.cve.org/CVERecord?id=CVE-2010-3448"],"bugs":["https://launchpad.net/bugs/706999"],"patches":{"linux-source-2.6.15":[],"linux":["break-fix: - b525c06cdbd8a3963f0173ccd23f9147d4c384b5"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.86","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.73","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-19.28","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-1.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-2.9","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.39-0.0","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.1.0-1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.6.39-0.0","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2.6.39-0.0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1600.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.27","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.32-304.8","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-203.15","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-409.25","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1073-1","USN-1072-1","USN-1074-1","USN-1074-2","USN-1093-1"],"notices":[{"id":"USN-1073-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:15:38.718890","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nThomas Pollet discovered that the RDS network protocol did not\ncheck certain iovec buffers. A local attacker could exploit this\nto crash the system or possibly execute arbitrary code as the root\nuser. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as\nthe root user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly\nclear kernel memory. A local attacker could exploit this to read kernel\nstack memory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-ec2","version":"2.6.31-307.27","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.73","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.27"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.73"}]},"type":"USN","cves_ids":["CVE-2010-4078","CVE-2010-4074","CVE-2010-3448","CVE-2010-0435","CVE-2010-3698","CVE-2010-3859","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4073","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4165","CVE-2010-4169","CVE-2010-4248","CVE-2010-4249"]},{"id":"USN-1072-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T22:59:02.971277","description":"Gleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nDan Jacobson discovered that ThinkPad video output was not correctly\naccess controlled. A local attacker could exploit this to hang the system,\nleading to a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-3698)\n\nIt was discovered that Xen did not correctly clean up threads. A local\nattacker in a guest system could exploit this to exhaust host system\nresources, leading to a denial of serivce. (CVE-2010-3699)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4248)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-28.86","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.86","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.86"}]},"type":"USN","cves_ids":["CVE-2010-3699","CVE-2010-0435","CVE-2010-2943","CVE-2010-3296","CVE-2010-3297","CVE-2010-3448","CVE-2010-3698","CVE-2010-3858","CVE-2010-3859","CVE-2010-3873","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4072","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4083","CVE-2010-4157","CVE-2010-4160","CVE-2010-4248"]},{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-4265","published":"2010-12-30T21:00:00","updated_at":"2025-08-04T19:23:54.522316+00:00","description":"\nThe\norg.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run\nmethod in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2\nin Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP)\n4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service\n(daemon outage) by establishing a bisocket control connection TCP session,\nand then not sending any application data, related to a missing\nCVE-2010-3862 patch. NOTE: this can be considered a duplicate of\nCVE-2010-3862 because a missing patch should not be assigned a separate CVE\nidentifier.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"probably RH specific as it's a missing patch for CVE-2010-3862"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4265"],"bugs":["https://issues.jboss.org/browse/JBREM-1261","https://issues.jboss.org/browse/JBPAPP-5253","https://bugzilla.redhat.com/show_bug.cgi?id=660623"],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3878","published":"2010-12-30T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in the JMX Console in Red\nHat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3\nbefore 4.3.0.CP09 allows remote attackers to hijack the authentication of\nadministrators for requests that deploy WAR files.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian says not affected, need to check."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3878"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=604617","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581226"],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3862","published":"2010-12-30T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe\norg.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run\nmethod in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2\nin Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP)\n4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka\nJBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon\noutage) by establishing a bisocket control connection TCP session, and then\nnot sending any application data.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian says not affected, need to check."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3862"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=641389","https://issues.jboss.org/browse/JBREM-1261","https://issues.jboss.org/browse/JBPAPP-5253","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581226"],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3708","published":"2010-12-30T21:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe serialization implementation in JBoss Drools in Red Hat JBoss\nEnterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before\n4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the\nembedding of class files, which allows remote attackers to execute\narbitrary code via a crafted static initializer.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian says not affected. need to check."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3708"],"bugs":["https://issues.jboss.org/browse/SOA-2319","https://bugzilla.redhat.com/show_bug.cgi?id=633859","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581226"],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4161","published":"2010-12-30T19:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build\nof the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows\nattackers to cause a denial of service (deadlock and system hang) by\nsending UDP traffic to a socket that has a crafted socket filter, a related\nissue to CVE-2010-4158.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"RH bug says introduced in commit 93821778 and fixed in\ncommit fda9ef5d."},{"author":"jdstrand","note":"introduced in 57fe93b374a6b8711995c2d466c502af9f3a08bb from\n2010/11/10"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-4161"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=651698","https://bugzilla.redhat.com/show_bug.cgi?id=652534"],"patches":{"linux-source-2.6.15":[],"linux":[],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-4352","published":"2010-12-30T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows\nlocal users to cause a denial of service (daemon crash) via a message\ncontaining many nested variants.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"requires unprivileged user account"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://openwall.com/lists/oss-security/2010/12/16/3","http://www.remlab.net/op/dbus-variant-recursion.shtml","https://ubuntu.com/security/notices/USN-1044-1","https://www.cve.org/CVERecord?id=CVE-2010-4352"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=663673","https://bugs.freedesktop.org/show_bug.cgi?id=32321","https://bugs.edge.launchpad.net/ubuntu/+source/dbus/+bug/688992"],"patches":{"dbus":["upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=7d65a3a6ed8815e34a99c680ac3869fde49dbbd4"]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.20-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.16-0ubuntu9.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.16-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.4.0-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1044-1"],"notices":[{"id":"USN-1044-1","title":"D-Bus vulnerability","summary":"A local attacker could send crafted input to D-Bus and cause it to crash.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-01-18T18:18:12.550194","description":"Remi Denis-Courmont discovered that D-Bus did not properly validate the\nnumber of nested variants when validating D-Bus messages. A local attacker\ncould exploit this to cause a denial of service.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"dbus","version":"1.1.20-1ubuntu3.4","description":"simple interprocess messaging system","is_source":true},{"name":"libdbus-1-3","version":"1.1.20-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.1.20-1ubuntu3.4"}],"lucid":[{"name":"dbus","version":"1.2.16-2ubuntu4.1","description":"simple interprocess messaging system","is_source":true},{"name":"libdbus-1-3","version":"1.2.16-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.1"}],"maverick":[{"name":"dbus","version":"1.4.0-0ubuntu1.1","description":"simple interprocess messaging system","is_source":true},{"name":"libdbus-1-3","version":"1.4.0-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.0-0ubuntu1.1"}],"karmic":[{"name":"dbus","version":"1.2.16-0ubuntu9.1","description":"simple interprocess messaging system","is_source":true},{"name":"libdbus-1-3","version":"1.2.16-0ubuntu9.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-0ubuntu9.1"}]},"type":"USN","cves_ids":["CVE-2010-4352"]}]},{"id":"CVE-2010-4342","published":"2010-12-30T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe aun_incoming function in net/econet/af_econet.c in the Linux kernel\nbefore 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause\na denial of service (NULL pointer dereference and OOPS) by sending an Acorn\nUniversal Networking (AUN) packet over UDP.","ubuntu_description":"\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://openwall.com/lists/oss-security/2010/12/09/1","https://ubuntu.com/security/notices/USN-1081-1","https://ubuntu.com/security/notices/USN-1119-1","https://ubuntu.com/security/notices/USN-1111-1","https://ubuntu.com/security/notices/USN-1133-1","https://ubuntu.com/security/notices/USN-1141-1","https://ubuntu.com/security/notices/USN-1162-1","https://ubuntu.com/security/notices/USN-1164-1","https://ubuntu.com/security/notices/USN-1167-1","https://ubuntu.com/security/notices/USN-1159-1","https://ubuntu.com/security/notices/USN-1187-1","https://www.cve.org/CVERecord?id=CVE-2010-4342"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=4e085e76cbe558b79b54cbab772f61185879bc64"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-29.89","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-32.62","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-27.47","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.37-10.24","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-316.30","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-609.26","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-28.50~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-217.34","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-417.34","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-57.96","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.37~rc6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1164-1","USN-1141-1","USN-1133-1","USN-1162-1","USN-1111-1","USN-1081-1","USN-1187-1","USN-1119-1","USN-1159-1"],"notices":[{"id":"USN-1164-1","title":"Linux kernel vulnerabilities (i.MX51)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-06T13:09:52.089799","description":"\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1748)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-609.26","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-609-imx51","version":"2.6.31-609.26","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-609.26"}]},"type":"USN","cves_ids":["CVE-2010-4529","CVE-2010-4342","CVE-2010-3877","CVE-2010-3876","CVE-2010-3875","CVE-2010-4258","CVE-2010-4164","CVE-2010-3873","CVE-2010-4346","CVE-2010-4527","CVE-2010-3865","CVE-2010-3874","CVE-2010-3880","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4248","CVE-2010-4565","CVE-2010-4655","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-1017","CVE-2011-1182","CVE-2011-1494","CVE-2011-1495","CVE-2011-1593","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022"]},{"id":"USN-1141-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel vulnerabilities have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-01T00:00:41.970993","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-316.31","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-32.62","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-32-386","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-316-ec2","version":"2.6.32-316.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-316.31"},{"name":"linux-image-2.6.32-32-lpia","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-ia64","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-versatile","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-server","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc64-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-generic-pae","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-generic","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-virtual","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-sparc64-smp","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-powerpc","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-preempt","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"},{"name":"linux-image-2.6.32-32-sparc64","version":"2.6.32-32.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-32.62"}]},"type":"USN","cves_ids":["CVE-2011-1573","CVE-2010-4263","CVE-2010-4243","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2010-4656","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1093","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1133-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-05-24T16:43:41.053544","description":"\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-29.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-29-sparc64","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-rt","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-386","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-itanium","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-hppa32","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-openvz","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-generic","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-xen","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-powerpc","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-powerpc-smp","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-hppa64","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-server","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-powerpc64-smp","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-lpia","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-virtual","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-mckinley","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-sparc64-smp","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"},{"name":"linux-image-2.6.24-29-lpiacompat","version":"2.6.24-29.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-29.89"}]},"type":"USN","cves_ids":["CVE-2010-4342","CVE-2010-4527","CVE-2010-4529","CVE-2011-0521"]},{"id":"USN-1162-1","title":"Linux kernel vulnerabilities (Marvell Dove)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-06-29T12:02:55.601188","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-217.34","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-217-dove","version":"2.6.32-217.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-217.34"}]},"type":"USN","cves_ids":["CVE-2010-4243","CVE-2010-4263","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2011-0463","CVE-2011-0695","CVE-2011-0711","CVE-2011-0726","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1090","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1573","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4611","CVE-2011-4913"]},{"id":"USN-1111-1","title":"Linux kernel vulnerabilities","summary":"Multiple flaws fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-05-05T21:15:33.314123","description":"Dan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-57.97","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-57-itanium","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa64-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-k8","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa32","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-386","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-powerpc","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-server-bigiron","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-server","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-k7","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-server","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-powerpc-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-686","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa32-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-generic","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-itanium-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-hppa64","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-powerpc64-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-sparc64","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-mckinley","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-mckinley-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-amd64-xeon","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"},{"name":"linux-image-2.6.15-57-sparc64-smp","version":"2.6.15-57.97","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-57.97"}]},"type":"USN","cves_ids":["CVE-2010-4164","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4527","CVE-2010-4529","CVE-2011-0521","CVE-2011-0695","CVE-2011-1017"]},{"id":"USN-1081-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-02T01:20:00.841133","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-27.48","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-27-generic-pae","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-server","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-generic","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-omap","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-versatile","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-powerpc64-smp","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"},{"name":"linux-image-2.6.35-27-virtual","version":"2.6.35-27.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-27.48"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-4079","CVE-2010-4083","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2011-0006","CVE-2011-1044","CVE-2011-4621"]},{"id":"USN-1187-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-08-09T03:09:05.161378","description":"\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered a leak in the kernel's inotify_init() system call.\nA local, unprivileged user could exploit this to cause a denial of service.\n(CVE-2010-4250)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.56~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.56~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.56~lucid1"}]},"type":"USN","cves_ids":["CVE-2010-3698","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4079","CVE-2010-4083","CVE-2010-4163","CVE-2010-4248","CVE-2010-4250","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529","CVE-2010-4565","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0463","CVE-2011-0521","CVE-2011-0695","CVE-2011-0711","CVE-2011-0712","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1169","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-4611","CVE-2011-4621","CVE-2011-4913"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1159-1","title":"Linux kernel vulnerabilities (Marvell Dove)","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-07-13T20:25:16.658771","description":"\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlexander Duyck discovered that the Intel Gigabit Ethernet driver did not\ncorrectly handle certain configurations. If such a device was configured\nwithout VLANs, a remote attacker could crash the system, leading to a\ndenial of service. (CVE-2010-4263)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg reported an error in the old ABI compatibility layer of ARM\nkernels. A local attacker could exploit this flaw to cause a denial of\nservice or gain root privileges. (CVE-2011-1759)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nMaynard Johnson discovered that on POWER7, certain speculative events may\nraise a performance monitor exception. A local attacker could exploit this\nto crash the system, leading to a denial of service. (CVE-2011-4611)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-417.34","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-417-dove","version":"2.6.32-417.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-417.34"}]},"type":"USN","cves_ids":["CVE-2010-4243","CVE-2010-4263","CVE-2010-4342","CVE-2010-4529","CVE-2010-4565","CVE-2011-0463","CVE-2011-0695","CVE-2011-0711","CVE-2011-0726","CVE-2011-1013","CVE-2011-1016","CVE-2011-1017","CVE-2011-1019","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1090","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1478","CVE-2011-1494","CVE-2011-1495","CVE-2011-1573","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1759","CVE-2011-1770","CVE-2011-1776","CVE-2011-2022","CVE-2011-2534","CVE-2011-3359","CVE-2011-3363","CVE-2011-4611","CVE-2011-4913"]}]}],"offset":71880,"limit":20,"total_results":79316}