USN-2545-1

    Dashboard / Vulnerabilities / USN-2545-1

    USN-2545-1

    Published: 24 Mar 2015Last Modified: 10 Feb 2026

    Summary: linux-lts-utopic vulnerabilities

    Details: A flaw was discovered in the automatic loading of modules in the crypto subsystem of the Linux kernel. A local user could exploit this flaw to load installed kernel modules, increasing the attack surface and potentially using this to gain administrative privileges. (CVE-2013-7421) A flaw was discovered in the crypto subsystem when screening module names for automatic module loading if the name contained a valid crypto module name, eg. vfat(aes). A local user could exploit this flaw to load installed kernel modules, increasing the attack surface and potentially using this to gain administrative privileges. (CVE-2014-9644) Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP (Stream Control Transmission Protocol) subsystem during INIT collisions. A remote attacker could exploit this flaw to cause a denial of service (system crash) or potentially escalate their privileges on the system. (CVE-2015-1421) Marcelo Leitner discovered a flaw in the Linux kernel's routing of packets to too many different dsts/too fast. A remote attacker can exploit this flaw to cause a denial of service (system crash). (CVE-2015-1465)

    Affected packages

    Package

    Name: linux-lts-utopic

    Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.16.0-33.44~14.04.1

    Affected versions

    3.16.0-25.33~14.04.2
    3.16.0-26.35~14.04.1
    3.16.0-28.37~14.04.1
    3.16.0-28.38~14.04.1
    3.16.0-29.39~14.04.1
    3.16.0-30.40~14.04.1
    3.16.0-31.41~14.04.1
    3.16.0-31.43~14.04.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High