USN-2848-1
Dashboard / Vulnerabilities / USN-2848-1
USN-2848-1
Summary: linux vulnerabilities
Details: Felix Wilhelm discovered a race condition in the Xen paravirtualized drivers which can cause double fetch vulnerabilities. An attacker in the paravirtualized guest could exploit this flaw to cause a denial of service (crash the host) or potentially execute arbitrary code on the host. (CVE-2015-8550) Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not perform consistency checks on the device's state. An attacker could exploit this flaw to cause a denial of service (NULL dereference) on the host. (CVE-2015-8551) Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not perform consistency checks on the device's state. An attacker could exploit this flaw to cause a denial of service by flooding the logging system with WARN() messages causing the initial domain to exhaust disk space. (CVE-2015-8552) Jann Horn discovered a ptrace issue with user namespaces in the Linux kernel. The namespace owner could potentially exploit this flaw by ptracing a root owned process entering the user namespace to elevate its privileges and potentially gain access outside of the namespace. (http://bugs.launchpad.net/bugs/1527374, CVE-2015-8709)
References: https://ubuntu.com/security/notices/USN-2848-1, https://ubuntu.com/security/CVE-2015-8550, https://ubuntu.com/security/CVE-2015-8551, https://ubuntu.com/security/CVE-2015-8552, https://ubuntu.com/security/CVE-2015-8709
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
