USN-3405-1
Dashboard / Vulnerabilities / USN-3405-1
USN-3405-1
Summary: linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities
Details: It was discovered that a use-after-free vulnerability existed in the POSIX message queue implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-11176) Huang Weller discovered that the ext4 filesystem implementation in the Linux kernel mishandled a needs-flushing-before-commit list. A local attacker could use this to expose sensitive information. (CVE-2017-7495) It was discovered that a buffer overflow existed in the Broadcom FullMAC WLAN driver in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-7541) It was discovered that the Linux kernel did not honor the UEFI secure boot mode when performing a kexec operation. A local attacker could use this to bypass secure boot restrictions. (CVE-2015-7837)
References: https://ubuntu.com/security/notices/USN-3405-1, https://ubuntu.com/security/CVE-2015-7837, https://ubuntu.com/security/CVE-2017-7495, https://ubuntu.com/security/CVE-2017-7541, https://ubuntu.com/security/CVE-2017-11176
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
