Canonical fixes six Ubuntu 15.10 and 14.04 kernel Vulnerabilities

Source: Internet
Author: User

Canonical fixes six Ubuntu 15.10 and 14.04 kernel Vulnerabilities

In April 6, Canonical released Kernel updates for Ubuntu 15.10 (Wily Werewolf), Ubuntu 15.10 for Raspberry Pi 2, and Ubuntu 14.04 LTS (Trusty Tahr) systems, this Kernel update fixes six known and newly discovered Linux Kernel vulnerabilities.

A total of six Linux kernel vulnerabilities are mentioned in the latest security notice of Canonical, four of which affect the Ubuntu 14.04 LTS system. The first vulnerability lies in the CXGB3 driver in Linux Kernel, which allows local attackers to cause system crashes, resulting in DoS or code execution.

The second security vulnerability lies in the Linux Kernel EVM (extended verification module) component. if attacked, system integrity will be affected. The third problem lies in the cache restriction allocated to the "Pipeline" by Linux Kernel, which can be exploited by local attackers to perform DoS attacks. The fourth security problem affects both Ubuntu 15.10 and Ubuntu 14.04 LTS systems. Security personnel found that Linux Kernel occupied the file descriptor originally opened using UNIX Socket, this may allow local attackers to initiate DoS attacks.

Only the Ubuntu15.10 issue is affected.

The fifth and sixth kernel vulnerabilities mentioned in the Security Bulletin only affect the Ubuntu 15.10 and Ubuntu 15.10 for Raspberry Pi 2 systems. One of these vulnerabilities is found in the Linux kernel USB vision driver, it will generate an incorrect health check report for endpoints and interfaces, allowing attacks to cause physical crashes.

The second vulnerability was found in the Berkeley Packet Filter (eBPF) Section of Linux kernel, allowing local attackers to perform DoS attacks or execute code.

Ubuntu users should update the kernel immediately at the appropriate time. After the update is completed, the system needs to be restarted.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.