USN-1057-1: Linux kernel vulnerabilities
Dave Chinner discovered that the XFS filesystem did not correctly order inode lookups when exported by NFS. A remote attacker could exploit this to read or write disk blocks that had changed file assignment or had become unlinked, leading to a loss of privacy. (CVE-2010-2943) Dan Rosenberg discovered that several network ioctls did not clear kernel memory correctly. A local user could exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2010-3297) Kees Cook and Vasiliy Kulikov discovered that the shm interface did not clear kernel memory correctly. A local attacker could exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2010-4072)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1057-1?
USN-1057-1 addresses a medium severity vulnerability that allows remote attackers to read or write disk blocks.
How do I fix USN-1057-1?
To fix USN-1057-1, update the linux-image packages to version 2.6.15-55.91 or later.
Which Ubuntu versions are affected by USN-1057-1?
USN-1057-1 affects Ubuntu version 6.06.
What is the nature of the vulnerability in USN-1057-1?
The vulnerability in USN-1057-1 is related to incorrect ordering of inode lookups in the XFS filesystem when exported by NFS.
Can USN-1057-1 lead to data loss?
Yes, USN-1057-1 can lead to a loss of privacy as it allows attackers to manipulate disk blocks that have changed file assignment or become unlinked.