USN-2420-1
Dashboard / Vulnerabilities / USN-2420-1
USN-2420-1
Summary: linux vulnerabilities
Details: A flaw was discovered in how the Linux kernel's KVM (Kernel Virtual Machine) subsystem handles the CR4 control register at VM entry on Intel processors. A local host OS user can exploit this to cause a denial of service (kill arbitrary processes, or system disruption) by leveraging /dev/kvm access. (CVE-2014-3690) Don Bailey discovered a flaw in the LZO decompress algorithm used by the Linux kernel. An attacker could exploit this flaw to cause a denial of service (memory corruption or OOPS). (CVE-2014-4608) Andy Lutomirski discovered a flaw in how the Linux kernel handles pivot_root when used with a chroot directory. A local user could exploit this flaw to cause a denial of service (mount-tree loop). (CVE-2014-7970) Andy Lutomirski discovered that the Linux kernel was not checking the CAP_SYS_ADMIN when remounting filesystems to read-only. A local user could exploit this flaw to cause a denial of service (loss of writability). (CVE-2014-7975)
References: https://ubuntu.com/security/notices/USN-2420-1, https://ubuntu.com/security/CVE-2014-3690, https://ubuntu.com/security/CVE-2014-4608, https://ubuntu.com/security/CVE-2014-7970, https://ubuntu.com/security/CVE-2014-7975
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
