You are here
Home > Preporuke > Ranjivosti jezgre operacijskog sustava

Ranjivosti jezgre operacijskog sustava

  • Detalji os-a: LUB
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2886-1
February 01, 2016

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
– linux: Linux kernel

Details:

It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)

It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)

郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)

Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7990)

It was discovered that the Btrfs implementation in the Linux kernel
incorrectly handled compressed inline extants on truncation. A local
attacker could use this to expose sensitive information. (CVE-2015-8374)

郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2015-8543)

Dmitry Vyukov discovered that the pptp implementation in the Linux kernel
did not verify an address length when setting up a socket. A local attacker
could use this to craft an application that exposed sensitive information
from kernel memory. (CVE-2015-8569)

David Miller discovered that the Bluetooth implementation in the Linux
kernel did not properly validate the socket address length for Synchronous
Connection-Oriented (SCO) sockets. A local attacker could use this to
expose sensitive information. (CVE-2015-8575)

It was discovered that the Linux kernel’s Filesystem in Userspace (FUSE)
implementation did not handle initial zero length segments properly. A
local attacker could use this to cause a denial of service (unkillable
task). (CVE-2015-8785)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.2.0-98-generic 3.2.0-98.138
linux-image-3.2.0-98-generic-pae 3.2.0-98.138
linux-image-3.2.0-98-highbank 3.2.0-98.138
linux-image-3.2.0-98-omap 3.2.0-98.138
linux-image-3.2.0-98-powerpc-smp 3.2.0-98.138
linux-image-3.2.0-98-powerpc64-smp 3.2.0-98.138
linux-image-3.2.0-98-virtual 3.2.0-98.138

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2886-1
CVE-2013-7446, CVE-2015-7513, CVE-2015-7799, CVE-2015-7990,
CVE-2015-8374, CVE-2015-8543, CVE-2015-8569, CVE-2015-8575,
CVE-2015-8785

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-98.138

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJWr9woAAoJEC8Jno0AXoH07SoP/1OiCQpkfDMqYVv7ZIkM2I10
1rhOYMSsmMHqR8eC1EfYF0ZuL15VOdZvCtSiJnt0YQIe3ygvH2L/zYwh/xXQbDIz
lLwvbNxLnPYN9D59ORxVGcHZLsm+z1wwv6jP2KQKjvYczzIeIZDzWI34DlVaV2a/
sy6ktbxMRY7JpVryOiKlBCbHzNDvRCECxqHu/jTe1BnfkNX1tKjZaFmwAwj0NVRV
pOvTrJHBmARcyuZdua1A7d5L4OZ4sKWiqYTqF8NwMnOgDr5XvvznHDvXW5K6tbLT
mqSxPgWG5QH7tLhTpNtLI+iuLb8zdpQ/8z5/eZySuCy/YgEEQ3h5FPmXS3UpsAyi
+PuNeh2CuMBm9j0rpOl4nuWEGibdufL7lqDXCoE1VkBKppZXr0NR0ZwluWz9vaeC
oUKzo/e3Qgbxb/1N4lRnyVIN7ImZ7aBIOdm/ICM+GkxwJKFaL7xrILVuh2BmKm2A
e1w82Z9TU/n3Ft9X3uyERVaT5VyJLgD8Q/k8h4JB3YaxTfO+SuzOxH5UHy7uLLn8
vx3ntxm/IFfjpilaC6Arc5DpXPPZMUFpapjbfBOoYgLVuXvNdC/8FkmJiKYUPCny
QbNn+cMd7PjiXhJSvkl0UaWDgiKFFbRVeFJA243EYL+n31YMXZW10akxZkZsMJND
/eipydiY5Q8qUkZiWKN0
=XR6+
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-2888-1
February 02, 2016

linux-lts-utopic vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
– linux-lts-utopic: Linux hardware enablement kernel from Utopic

Details:

It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)

It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)

It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)

Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7990)

It was discovered that the Btrfs implementation in the Linux kernel
incorrectly handled compressed inline extants on truncation. A local
attacker could use this to expose sensitive information. (CVE-2015-8374)

郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2015-8543)

Dmitry Vyukov discovered that the pptp implementation in the Linux kernel
did not verify an address length when setting up a socket. A local attacker
could use this to craft an application that exposed sensitive information
from kernel memory. (CVE-2015-8569)

David Miller discovered that the Bluetooth implementation in the Linux
kernel did not properly validate the socket address length for Synchronous
Connection-Oriented (SCO) sockets. A local attacker could use this to
expose sensitive information. (CVE-2015-8575)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-3.16.0-60-generic 3.16.0-60.80~14.04.1
linux-image-3.16.0-60-generic-lpae 3.16.0-60.80~14.04.1
linux-image-3.16.0-60-lowlatency 3.16.0-60.80~14.04.1
linux-image-3.16.0-60-powerpc-e500mc 3.16.0-60.80~14.04.1
linux-image-3.16.0-60-powerpc-smp 3.16.0-60.80~14.04.1
linux-image-3.16.0-60-powerpc64-emb 3.16.0-60.80~14.04.1
linux-image-3.16.0-60-powerpc64-smp 3.16.0-60.80~14.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2888-1
CVE-2013-7446, CVE-2015-7513, CVE-2015-7550, CVE-2015-7990,
CVE-2015-8374, CVE-2015-8543, CVE-2015-8569, CVE-2015-8575

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-60.80~14.04.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJWsApxAAoJEC8Jno0AXoH03X0P/ivhVVxLRdFSE2PEYPHs9c1b
psuiKgmxM+riIfZCjrtYf6zz6J6liIw6MRCo+UR17nJd8I7yu7cvHWK2MEEvpc3B
CvT+n5ivYx1aLZYAShZusZaWlSuMscuhwHeQz6IiBdvzlmx1eQ/vmMiyq4SLdFhm
XYLBCiNlmSnUeYG4j2B6EETIHWpmg9pMm4hvlZWjVp5iLUs24LlaFPJoGuNqzNxa
E8ntjp4D+E0mgzupfBXAmP/kyUfu+lXateSTycEROSCx1Tel1Hj3QYqv9HE9fA3x
AALq8LR92vQuEUJf7lK5oa19SDaXynJKuwvfx89NJSnca0kYlHxFv03BzYQsAEBA
FYSejLpFTqwikAIAmdj9V7UKgPwQo0/7zPWiCXazGna4JhKjIqhkri+ZubafxxHg
F3cdoLtT+OijDddXYg6GVYB8YR5iyZ0SR1Wb4Mb7vK1O+v+zHpCWp91zMDy3q/1S
sZ7NRFtawp4CD7o5FbuyHs5JATalFOlQ9hHtuRm3OrmF5eiLtwY/sycD7ehRquHo
xsplMEJUy44tsEX4O8T3BVBwWytnU2EszUnbFfrOfbazf4nIEFyfGEXWKx26HPZw
0dzGmuI6Xwk8FmZpl5ZoSziKmxqPP1zdpA4CG9SkK5VckpWj7DPbTEGouJ/M5DuJ
q/6nCwyZiW6f9SOf8psA
=5m6C
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-2890-1
February 02, 2016

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
– linux: Linux kernel

Details:

It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)

It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)

It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)

Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7990)

It was discovered that the Btrfs implementation in the Linux kernel
incorrectly handled compressed inline extants on truncation. A local
attacker could use this to expose sensitive information. (CVE-2015-8374)

郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2015-8543)

Dmitry Vyukov discovered that the pptp implementation in the Linux kernel
did not verify an address length when setting up a socket. A local attacker
could use this to craft an application that exposed sensitive information
from kernel memory. (CVE-2015-8569)

David Miller discovered that the Bluetooth implementation in the Linux
kernel did not properly validate the socket address length for Synchronous
Connection-Oriented (SCO) sockets. A local attacker could use this to
expose sensitive information. (CVE-2015-8575)

It was discovered that the netfilter Network Address Translation (NAT)
implementation did not ensure that data structures were initialized when
handling IPv4 addresses. An attacker could use this to cause a denial of
service (system crash). (CVE-2015-8787)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
linux-image-4.2.0-27-generic 4.2.0-27.32
linux-image-4.2.0-27-generic-lpae 4.2.0-27.32
linux-image-4.2.0-27-lowlatency 4.2.0-27.32
linux-image-4.2.0-27-powerpc-e500mc 4.2.0-27.32
linux-image-4.2.0-27-powerpc-smp 4.2.0-27.32
linux-image-4.2.0-27-powerpc64-emb 4.2.0-27.32
linux-image-4.2.0-27-powerpc64-smp 4.2.0-27.32

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2890-1
CVE-2013-7446, CVE-2015-7513, CVE-2015-7550, CVE-2015-7990,
CVE-2015-8374, CVE-2015-8543, CVE-2015-8569, CVE-2015-8575,
CVE-2015-8787

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.2.0-27.32

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJWsA9vAAoJEC8Jno0AXoH0uDAQAJmLrlVTRmIvpEkkzaoG3Tey
ZrHIWT5Poj17/u8HeWBTDB8fyM2SU0BEpYOApRBNj0K2IjzeImTzwUBSarxhLHqc
KOQ+U+qroWQRtQPYvwSCinj9VvWLrSPoRmkKkS1YYgH1cUDJOZjagiXhFAbvnLaM
uH3d2nKUk3xEfYNQP5PqCCScXzsgLVJvWv5TeXshm0vvA5lGN0kM9NyfBXIo7968
FNpbmBLPPui//b1jLr2Q3rI/k8xOuXxMr9fpNSWdLr1vpWa6l7oXTqHnjPto1OB+
Wd1bU+hBBIgtJl4bGP8i50dGLIoNK/H1J9bP/7sdBznAZHUweX8tAcWRZAwTg4nF
b3jLi+m9rd7YHpeEyMtEfVtQ3SmvkzVZALOL5OhQ3BQly9ScwQ/Q9a2SzptfTu27
0CCT6Akzc68GCPIUc3TSJZ7Y1N/0i4u7jXrPnLFo2darrJS0/V7HSg/jkjywUaNt
dPCMRTsKaWadyNh4kZAVY/1/gfCH0kgGwqvQ8q0zHiesdjfoLEDoGVRRIFAXkFW/
d76aQyx7a/KPuo14+KfV81WaxjNjMudFH3BENi6dIlsQXKVv1HePMix7cstoam2v
puCEW3SJ0R6zM9R5uIJZQS3gVbgbk2L/DSbpqH0qWG9dD1I4v/k8dYHPb51LqVr9
jRRJqy8rkDbCYVevqwR5
=DiBI
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-2890-2
February 02, 2016

linux-lts-wily vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
– linux-lts-wily: Linux hardware enablement kernel from Wily

Details:

It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)

It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)

It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)

Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7990)

It was discovered that the Btrfs implementation in the Linux kernel
incorrectly handled compressed inline extants on truncation. A local
attacker could use this to expose sensitive information. (CVE-2015-8374)

郭永刚 discovered that the Linux kernel networking implementation did
not validate protocol identifiers for certain protocol families, A local
attacker could use this to cause a denial of service (system crash) or
possibly gain administrative privileges. (CVE-2015-8543)

Dmitry Vyukov discovered that the pptp implementation in the Linux kernel
did not verify an address length when setting up a socket. A local attacker
could use this to craft an application that exposed sensitive information
from kernel memory. (CVE-2015-8569)

David Miller discovered that the Bluetooth implementation in the Linux
kernel did not properly validate the socket address length for Synchronous
Connection-Oriented (SCO) sockets. A local attacker could use this to
expose sensitive information. (CVE-2015-8575)

It was discovered that the netfilter Network Address Translation (NAT)
implementation did not ensure that data structures were initialized when
handling IPv4 addresses. An attacker could use this to cause a denial of
service (system crash). (CVE-2015-8787)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-4.2.0-27-generic 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-generic-lpae 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-lowlatency 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc-e500mc 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc-smp 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc64-emb 4.2.0-27.32~14.04.1
linux-image-4.2.0-27-powerpc64-smp 4.2.0-27.32~14.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2890-2
http://www.ubuntu.com/usn/usn-2890-1
CVE-2013-7446, CVE-2015-7513, CVE-2015-7550, CVE-2015-7990,
CVE-2015-8374, CVE-2015-8543, CVE-2015-8569, CVE-2015-8575,
CVE-2015-8787

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-27.32~14.04.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJWsBFMAAoJEC8Jno0AXoH0W4EQAIpoYzNB3mrDxuJX3zNU7DfX
OVgZ6H9D9CCzwIGx1+4d3UDYNdqlbxxwlUKXmnxI4Yl5KUVU/7RV0EsSOZLGipax
boBHte8HImkHknKQ9OqKtQmyiRtZFPmVqX3Fq0mIPh24ubY6/BZy06UOy0ie+G25
vnmrXtoe+MzhaZ2Xp5o9V7y1TIMpp05PpVRQ/58my1XuZ+THjpcy205f4/VTzoV0
bKocoJ8mmCyvNG0+8tizcDte4KBZ/x8cCa/FhjcRH0yhfMG9sfaVwN6njMjfyVCM
ssDUVtyb8KWaN88U0XZY8Q8FK/nJheFTF5VdPTJkUFnYQQG7kUAJgJFWs3AhpGR2
QV7N0J3Gw9l7wDFnLNrPvbDW4nn4owAJkyBwrwQlBWy+qKna95WpTNEr0fT3YCEl
EaMcLrI2/G+1IBlMa8SgnQh+qHtRWCrgYBFC4nRKraaXkBk5p/FeRhL2qGrK5PWs
6gT1No7XRHcr9wIMdILZ2yOAhdlTyoygJTS4rzcQjWE66FqPiQhaGWQfqKDqnI0M
GQ8xwZ/W/WprAKNLsEXXtAq2T2KK9dcHCT7mWT91ctBeOT8th6pOfPiYy2/hEMjQ
XwZqYJEj5O9/Q1wLzsqCoOkWaQ7zlOkByDWMM874AlMToxZ/Tk3t9I3QskUH6Y2/
+DmihXDrW6v0rIVyjM9l
=ZFXM
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2016-02-0025-ADV
CveCVE-2013-7446 CVE-2015-7513 CVE-2015-7799 CVE-2015-7990 CVE-2015-8374 CVE-2015-8543 CVE-2015-8569 CVE-2015-8575 CVE-2015-8785 CVE-2015-7550 CVE-2015-8787
ID izvornikaUSN-2886-1 USN-2888-1 USN-2890-1 USN-2890-2
Proizvodlinux
Izvorhttp://www.ubuntu.com
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa curl

Otkriven je sigurnosni propust u programskom paketu curl za Fedoru 22. Propust se nalazio u funkciji ConnectionExists (lib/url.c) unutar biblioteke...

Close