USN-2635-1
Dashboard / Vulnerabilities / USN-2635-1
USN-2635-1
Summary: linux-lts-utopic vulnerabilities
Details: Xiong Zhou discovered a bug in the way the EXT4 filesystem handles fallocate zero range functionality when the page size is greater than the block size. A local attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2015-0275) Wen Xu discovered a use-after-free flaw in the Linux kernel's ipv4 ping support. A local user could exploit this flaw to cause a denial of service (system crash) or gain administrative privileges on the system. (CVE-2015-3636)
References: https://ubuntu.com/security/notices/USN-2635-1, https://ubuntu.com/security/CVE-2015-0275, https://ubuntu.com/security/CVE-2015-3636
Affected packages
Package
Name: linux-lts-utopic
Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
