USN-1023-1: Linux kernel vulnerabilities
Nelson Elhage discovered several problems with the Acorn Econet protocol driver. A local user could cause a denial of service via a NULL pointer dereference, escalate privileges by overflowing the kernel stack, and assign Econet addresses to arbitrary interfaces. (CVE-2010-3848, CVE-2010-3849, CVE-2010-3850) Brad Spengler discovered that the wireless extensions did not correctly validate certain request sizes. A local attacker could exploit this to read portions of kernel memory, leading to a loss of privacy. (CVE-2010-2955) Dan Rosenberg discovered that the VIA video driver did not correctly clear kernel memory. A local attacker could exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2010-4082) A flaw was discovered in the Linux kernel's splice system call. A local user could use this flaw to cause a denial of service (system crash). (CVE-2013-2128)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-1023-1?
The severity of USN-1023-1 is considered high due to potential denial of service and privilege escalation vulnerabilities.
How do I fix USN-1023-1?
To fix USN-1023-1, update your system to the latest kernel version specified in the Ubuntu security notice.
What vulnerabilities are associated with USN-1023-1?
USN-1023-1 addresses vulnerabilities including CVE-2010-3848, CVE-2010-3849, and CVE-2010-2955.
Who discovered the issue outlined in USN-1023-1?
The issue outlined in USN-1023-1 was discovered by Nelson Elhage.
Which Ubuntu versions are affected by USN-1023-1?
USN-1023-1 affects Ubuntu version 9.10 and its associated kernel images.