USN-4135-2
Dashboard / Vulnerabilities / USN-4135-2
USN-4135-2
Summary: linux, linux-aws, linux-azure, linux-lts-trusty, linux-lts-xenial vulnerabilities
Details: Peter Pi discovered a buffer overflow in the virtio network backend (vhost_net) implementation in the Linux kernel. An attacker in a guest may be able to use this to cause a denial of service (host OS crash) or possibly execute arbitrary code in the host OS. (CVE-2019-14835) It was discovered that the Linux kernel on PowerPC architectures did not properly handle Facility Unavailable exceptions in some situations. A local attacker could use this to expose sensitive information. (CVE-2019-15030) It was discovered that the Linux kernel on PowerPC architectures did not properly handle exceptions on interrupts in some situations. A local attacker could use this to expose sensitive information. (CVE-2019-15031)
References: https://ubuntu.com/security/notices/USN-4135-2, https://ubuntu.com/security/CVE-2019-14835, https://ubuntu.com/security/CVE-2019-15030, https://ubuntu.com/security/CVE-2019-15031
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
