USN-2751-1

    Dashboard / Vulnerabilities / USN-2751-1

    USN-2751-1

    Published: 29 Sept 2015Last Modified: 10 Feb 2026

    Summary: linux-lts-vivid vulnerabilities

    Details: Benjamin Randazzo discovered an information leak in the md (multiple device) driver when the bitmap_info.file is disabled. A local privileged attacker could use this to obtain sensitive information from the kernel. (CVE-2015-5697) Marc-André Lureau discovered that the vhost driver did not properly release the userspace provided log file descriptor. A privileged attacker could use this to cause a denial of service (resource exhaustion). (CVE-2015-6252)

    Affected packages

    Package

    Name: linux-lts-vivid

    Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.19.0-30.33~14.04.1

    Affected versions

    3.19.0-18.18~14.04.1
    3.19.0-20.20~14.04.1
    3.19.0-21.21~14.04.1
    3.19.0-22.22~14.04.1
    3.19.0-23.24~14.04.1
    3.19.0-25.26~14.04.1
    3.19.0-26.28~14.04.1
    3.19.0-28.30~14.04.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-2751-1 | CVE-DB