MGASA-2015-0439
Dashboard / Vulnerabilities / MGASA-2015-0439
Summary: Updated kernel-linus packages fixes security vulnerability
Details: This update of kernel-linus provides the upstream 4.1.12 longterm kernel and fixes at least the following security issue: Moein Ghasemzadeh discovered that the USB WhiteHEAT serial driver contained hardcoded attributes about the USB devices. An attacker could construct a fake WhiteHEAT USB device that, when inserted, causes a denial of service (system crash) (CVE-2015-5257). It also fixes various upstream bugs, for more info see the referenced changelogs:
References: https://advisories.mageia.org/MGASA-2015-0439.html, https://bugs.mageia.org/show_bug.cgi?id=17066, https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.9, https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.10, https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.11, https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.12
Affected packages
Package
Name: kernel-linus
Purl: pkg:rpm/mageia/kernel-linus?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
