{"cves":[{"id":"CVE-2010-3198","published":"2010-09-08T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows\nremote attackers to cause a denial of service (crash of worker threads) via\nvectors that trigger uncaught exceptions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3198"],"bugs":[""],"patches":{"zope2.11":["upstream: http://svn.zope.org/Zope/branches/2.11/?rev=116088&view=rev"],"zope2.10":["upstream: http://svn.zope.org/Zope/branches/2.10/?rev=116087&view=rev"]},"tags":{},"packages":[{"name":"zope2.10","source":"https://ubuntu.com/security/cve?package=zope2.10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.10","debian":"https://tracker.debian.org/pkg/zope2.10","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.10.12","component":null,"pocket":"security"}]},{"name":"zope2.11","source":"https://ubuntu.com/security/cve?package=zope2.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zope2.11","debian":"https://tracker.debian.org/pkg/zope2.11","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.11.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2958","published":"2010-09-08T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in libraries/Error.class.php in\nphpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web\nscript or HTML via vectors related to a PHP backtrace and error messages\n(aka debugging messages), a different vulnerability than CVE-2010-3056.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2958"],"bugs":[""],"patches":{"phpmyadmin":["upstream: http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=133a77fac7d31a38703db2099a90c1b49de62e37"]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"dapper","status":"not-affected","description":"3.x only","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"3.x only","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4:3.3.7-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4:3.3.7-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"4:3.3.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"4:3.3.7-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"4:3.3.7-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"4:3.3.7-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"4:3.3.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2961","published":"2010-09-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmountall.c in mountall before 2.15.2 uses 0666 permissions for the\nroot.rules file, which allows local users to gain privileges by modifying\nthis file.","ubuntu_description":"\nAlasdair MacGregor discovered that mountall created a udev rule file\nwith world-writable permissions. A local attacker could exploit this\nunder certain conditions to cause udev to execute arbitrary commands as\nthe root user.","notes":[{"author":"kees","note":"luckily, udev doesn't use inotify on this directory at boot time, so\nudev needs to be reloaded before this is really ugly."}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-985-1","https://www.cve.org/CVERecord?id=CVE-2010-2961"],"bugs":["https://bugs.edge.launchpad.net/ubuntu/+source/mountall/+bug/591807"],"patches":{"mountall":[]},"tags":{},"packages":[{"name":"mountall","source":"https://ubuntu.com/security/cve?package=mountall","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mountall","debian":"https://tracker.debian.org/pkg/mountall","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.15.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-985-1"],"notices":[{"id":"USN-985-1","title":"mountall vulnerability","summary":"Local root escalation via writable udev rules.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-08T18:53:30.733188","description":"Alasdair MacGregor discovered that mountall created a udev rule file\nwith world-writable permissions. A local attacker could exploit this\nunder certain conditions to cause udev to execute arbitrary commands as\nthe root user.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"mountall","version":"2.15.2","description":"filesystem mounting tool","is_source":true},{"name":"mountall","version":"2.15.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mountall","version_link":"https://launchpad.net/ubuntu/+source/mountall/2.15.2"}]},"type":"USN","cves_ids":["CVE-2010-2961"]}]},{"id":"CVE-2010-2960","published":"2010-09-08T00:00:00","updated_at":"2025-08-25T19:59:14.932038+00:00","description":"\nThe keyctl_session_to_parent function in security/keys/keyctl.c in the\nLinux kernel 2.6.35.4 and earlier expects that a certain parent session\nkeyring exists, which allows local users to cause a denial of service (NULL\npointer dereference and system crash) or possibly have unspecified other\nimpact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.","ubuntu_description":"\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice.","notes":[{"author":"kees","note":"system crash without pam_keyinit"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1083-1","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1119-1","https://www.cve.org/CVERecord?id=CVE-2010-2960"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff_plain;h=9d1ac65a9698513d00e5608d93fca0c53f536c14","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff_plain;h=3d96406c7da1ed5811ea52a3b0905f4f0e295376","lucid: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2960/patches/lucid/linux/0001-KEYS-Fix-RCU-no-lock-warning-in-keyctl_session_to_pare.txt","lucid: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2960/patches/lucid/linux/0002-KEYS-Fix-bug-in-keyctl_session_to_parent-if-parent-has.txt"],"linux-mvl-dove":[],"linux-ec2":[],"linux-fsl-imx51":[],"linux-lts-backport-maverick":[],"linux-ti-omap4":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-25.45","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-216.33","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-416.33","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1083-1","USN-1119-1","USN-1000-1","USN-1093-1"],"notices":[{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-2955","published":"2010-09-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the\nLinux kernel before 2.6.36-rc3-next-20100831 does not properly initialize\ncertain structure members, which allows local users to leverage an\noff-by-one error in the ioctl_standard_iw_point function in\nnet/wireless/wext-core.c, and obtain potentially sensitive information from\nkernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that\nspecifies a large buffer size.","ubuntu_description":"\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1119-1","https://ubuntu.com/security/notices/USN-1023-1","https://www.cve.org/CVERecord?id=CVE-2010-2955"],"bugs":[""],"patches":{"linux-backports-modules-2.6.24":["hardy: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2955/patches/hardy/lbm/0001-wireless-extensions-fix-kernel-heap-content-leak.txt"],"linux-backports-modules-2.6.28":["jaunty: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2955/patches/jaunty/lbm/0001-wireless-extensions-fix-kernel-heap-content-leak.txt"],"linux-source-2.6.15":[],"linux-backports-modules-2.6.32":["lucid: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2955/patches/lucid/lbm/0001-wireless-extensions-fix-kernel-heap-content-leak.txt"],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=42da2f948d949efd0111309f5827bf0298bcc9a4","jaunty: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2955/patches/jaunty/linux/0001-wireless-extensions-fix-kernel-heap-content-leak.txt","karmic: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2955/patches/karmic/linux/0001-wireless-extensions-fix-kernel-heap-content-leak.txt","lucid: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2955/patches/lucid/linux/0001-wireless-extensions-fix-kernel-heap-content-leak.txt"],"linux-ti-omap4":[],"linux-mvl-dove":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-raspi2":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-26.47","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-22.34","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.37-2.9","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.39-0.0","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.1.0-1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.7.0-0.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1600.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-backports-modules-2.6.24","source":"https://ubuntu.com/security/cve?package=linux-backports-modules-2.6.24","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-backports-modules-2.6.24","debian":"https://tracker.debian.org/pkg/linux-backports-modules-2.6.24","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-backports-modules-2.6.28","source":"https://ubuntu.com/security/cve?package=linux-backports-modules-2.6.28","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-backports-modules-2.6.28","debian":"https://tracker.debian.org/pkg/linux-backports-modules-2.6.28","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-backports-modules-2.6.32","source":"https://ubuntu.com/security/cve?package=linux-backports-modules-2.6.32","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-backports-modules-2.6.32","debian":"https://tracker.debian.org/pkg/linux-backports-modules-2.6.32","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-310.21","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.10","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.4.0-1.3]]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.4.0-1.9]]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.1.10-8.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.1.10-8.28]]","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-22.34~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.5.0-18.29~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.8.0-19.30~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.11.0-13.20~precise2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.16.0-25.33~14.04.2]]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.19.0-18.18~14.04.1]]","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.0.0-3.18]]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-5.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.4.0-3.21]]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [3.4.0-4.19]]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-213.29","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-414.30","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.38-1309.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.6.38-1309.13","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2.6.38-1309.13","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1023-1","USN-1074-1","USN-1083-1","USN-1119-1","USN-1074-2","USN-1093-1"],"notices":[{"id":"USN-1023-1","title":"Linux kernel vulnerabilities","summary":"The Linux kernel could be made to run unauthorized programs with\nadministrator privileges.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2010-11-30T02:23:58.365703","description":"\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nA flaw was discovered in the Linux kernel's splice system call. A local\nuser could use this flaw to cause a denial of service (system crash).\n(CVE-2013-2128)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-28.81","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.81","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.81"}],"lucid":[{"name":"linux-ec2","version":"2.6.32-310.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-26.48","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-26-generic","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-sparc64-smp","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-preempt","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-powerpc-smp","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-versatile","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-powerpc64-smp","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-virtual","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-generic-pae","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-lpia","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-powerpc","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-310-ec2","version":"2.6.32-310.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-310.21"},{"name":"linux-image-2.6.32-26-sparc64","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-server","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-ia64","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"},{"name":"linux-image-2.6.32-26-386","version":"2.6.32-26.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-26.48"}],"maverick":[{"name":"linux","version":"2.6.35-23.41","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-23-powerpc64-smp","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-virtual","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-versatile","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-generic","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-powerpc-smp","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-powerpc","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-omap","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-generic-pae","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"},{"name":"linux-image-2.6.35-23-server","version":"2.6.35-23.41","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-23.41"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.90","description":"The Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.90"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.22","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.69","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.22"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.69","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.69"}]},"type":"USN","cves_ids":["CVE-2010-2955","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-4082","CVE-2013-2128"]},{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-2798","published":"2010-09-08T00:00:00","updated_at":"2025-08-25T19:58:50.871596+00:00","description":"\nThe gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel\nbefore 2.6.35 uses an incorrect size value in calculations associated with\nsentinel directory entries, which allows local users to cause a denial of\nservice (NULL pointer dereference and panic) and possibly have unspecified\nother impact by renaming a file in a GFS2 filesystem, related to the\ngfs2_rename function in fs/gfs2/ops_inode.c.","ubuntu_description":"\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-2798"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=728a756b8fcd22d80e2dbba8117a8a3aafd3f203","hardy: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2798/patches/hardy/linux/0001-GFS2-rename-causes-kernel-Oops.txt","jaunty: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2798/patches/jaunty/linux/0001-GFS2-rename-causes-kernel-Oops.txt","karmic: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2798/patches/karmic/linux/0001-GFS2-rename-causes-kernel-Oops.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.80","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.35","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2524","published":"2010-09-08T00:00:00","updated_at":"2025-08-25T19:58:22.919809+00:00","description":"\nThe DNS resolution functionality in the CIFS implementation in the Linux\nkernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a\nuser's keyring for the dns_resolver upcall in the cifs.upcall userspace\nhelper, which allows local users to spoof the results of DNS queries and\nperform arbitrary CIFS mounts via vectors involving an add_key call,\nrelated to a \"cache stuffing\" issue and MS-DFS referrals.","ubuntu_description":"\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation.","notes":[{"author":"sbeattie","note":"according to oss-security discussion, git commit 6103335de8afa5d780dcd512abe85c696af7b040\nintroduced the problem, so 2.6.25-rc1 onwards."},{"author":"smb","note":"Jaunty *may* be affected, but the problem is that there is no infra-\nstructure for thread credentials, so even if it is possible to back-\nport the whole thing it would be completely different and prone to\nbe incorrect. That together with the fact that Jaunty is EOL more or\nless I don't think we should put in much effort there."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-2524"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=4c0c03ca54f72fdd5912516ad0a23ec5cf01bda7","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2524/patches/karmic/linux/0001-CIFS-Fix-a-malicious-redirect-problem-in-the-DNS-looku.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"2.6.24","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-25.43","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.35","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"before 2.6.25-rc1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2495","published":"2010-09-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP\nimplementation in the Linux kernel before 2.6.34 does not properly validate\ncertain values associated with an interface, which allows attackers to\ncause a denial of service (NULL pointer dereference and OOPS) or possibly\nhave unspecified other impact via vectors related to a routing change.","ubuntu_description":"\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-2495"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=3feec9095d12e311b7d4eb7fe7e5dfa75d4a72a5","karmic: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2495/patches/karmic/linux/0001-l2tp-Fix-oops-in-pppol2tp_xmit.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.35","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2066","published":"2010-09-08T00:00:00","updated_at":"2025-08-25T19:57:07.609305+00:00","description":"\nThe mext_check_arguments function in fs/ext4/move_extent.c in the Linux\nkernel before 2.6.35 allows local users to overwrite an append-only file\nvia a MOVE_EXT ioctl call that specifies this file as a donor.","ubuntu_description":"\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss.","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-2066"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=1f5a81e41f8b1a782c68d3843e9ec1bfaadf7d72","karmic: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2066/patches/karmic/linux/0001-ext4-Make-sure-the-MOVE_EXT-ioctl-can-t-overwrite-appe.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no ext4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.35","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no ext4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2009-4895","published":"2010-09-08T00:00:00","updated_at":"2025-08-25T19:52:38.014832+00:00","description":"\nRace condition in the tty_fasync function in drivers/char/tty_io.c in the\nLinux kernel before 2.6.32.6 allows local users to cause a denial of\nservice (NULL pointer dereference and system crash) or possibly have\nunspecified other impact via unknown vectors, related to the put_tty_queue\nand __f_setown functions.  NOTE: the vulnerability was addressed in a\ndifferent way in 2.6.32.9.","ubuntu_description":"\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.","notes":[{"author":"sbeattie","note":"first patch (703625118069f9f8) was reverted and the second\npatch was used in 2.6.32.9, which fixes the issue \"properly\"."},{"author":"smb","note":"IMO the races in tty became visible when the BLK was pushed down into\nthe line disciplines and switch to unlocked ioctl in 2.6.26\n(04f378b198da233ca0aca341b113dc6579d46123), so Hardy and Dapper are not\naffected."}],"codename":null,"priority":"low","cvss3":4.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2009-4895"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=703625118069f9f8960d356676662d3db5a9d116","upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=80e1e823989ec44d8e35bdfddadbddcffec90424","jaunty: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2009-4895/patches/jaunty/linux/0001-Fix-race-in-tty_fasync-properly.txt","karmic: http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2009-4895/patches/karmic/linux/0001-Fix-race-in-tty_fasync-properly.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.32-15.21","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.6.35","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33-rc8, 2.6.32.9, 2.6.27.46","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-3259","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google\nChrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly\nrestrict read access to images derived from CANVAS elements, which allows\nremote attackers to bypass the Same Origin Policy and obtain potentially\nsensitive image data via a crafted web site.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-3259"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/65826"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.5-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.5-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.5-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3258","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe sandbox implementation in Google Chrome before 6.0.472.53 does not\nproperly deserialize parameters, which has unspecified impact and remote\nattack vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chromium-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3258"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3257","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in WebKit, as used in Apple Safari before\n4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and\nwebkitgtk before 1.2.6, allows remote attackers to execute arbitrary code\nor cause a denial of service (application crash) via vectors involving\nelement focus.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"qt4-x11 unmaintained upstream (see README.webkit for details)\nwebkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1006-1","https://www.cve.org/CVERecord?id=CVE-2010-3257"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/65748"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"webkit isn't built","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.2.5-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.2.5-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.2.5-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.5-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.5-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3256","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 6.0.472.53 does not properly limit the number of\nstored autocomplete entries, which has unspecified impact and attack\nvectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chromium-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3256"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3255","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly\nhandle counter nodes, which allows remote attackers to cause a denial of\nservice (memory corruption) or possibly have unspecified other impact via\nunknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nlooks chromium specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3255"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/66052"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3253","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe implementation of notification permissions in Google Chrome before\n6.0.472.53 allows attackers to cause a denial of service (memory\ncorruption) or possibly have unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3253"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/64647","upstream: http://trac.webkit.org/changeset/64651"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3252","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the Notifications presenter in Google\nChrome before 6.0.472.53 allows attackers to cause a denial of service or\npossibly have unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nnotifications aren't used in gtkwebkit"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3252"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/65742"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3251","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe WebSockets implementation in Google Chrome before 6.0.472.53 allows\nremote attackers to cause a denial of service (NULL pointer dereference and\napplication crash) via unspecified vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chromium-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3251"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3250","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 6.0.472.53 allows remote\nattackers to enumerate the set of installed extensions via unknown vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chromium-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3250"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3249","published":"2010-09-07T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 6.0.472.53 does not properly implement SVG filters,\nwhich allows remote attackers to cause a denial of service or possibly have\nunspecified other impact via unknown vectors, related to a \"stale pointer\"\nissue.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit is a fork of khtml from kdelibs. kdelibs5 is farther from\nit, while qt4-x11 attempts to unify khtml and webkit."},{"author":"mdeslaur","note":"webkitkde is a wrapper around qt4-x11's webkit.\nprobably chromium-specific."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3249"],"bugs":[""],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/60541"],"qt4-x11":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.0.472.53~r57914-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.472.53","component":null,"pocket":"security"}]},{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"no webkit","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72380,"limit":20,"total_results":79316}