First published: Tue Nov 29 2011(Updated: )
Andrea Righi discovered a race condition in the KSM memory merging support. If KSM was being used, a local attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-2183) Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly handled unlock requests. A local attacker could exploit this to cause a denial of service. (CVE-2011-2491) Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy. (CVE-2011-2494) Vasiliy Kulikov discovered that /proc/PID/io did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy. (CVE-2011-2495) It was discovered that the wireless stack incorrectly verified SSID lengths. A local attacker could exploit this to cause a denial of service or gain root privileges. (CVE-2011-2517) Christian Ohm discovered that the perf command looks for configuration files in the current directory. If a privileged user were tricked into running perf in a directory containing a malicious configuration file, an attacker could run arbitrary commands and possibly gain privileges. (CVE-2011-2905) Vasiliy Kulikov discovered that the Comedi driver did not correctly clear memory. A local attacker could exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2011-2909)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-2.6.38-13-powerpc | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-powerpc64-smp | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-generic-pae | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-versatile | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-generic | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-virtual | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-server | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-omap | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 | ||
All of | ||
ubuntu/linux-image-2.6.38-13-powerpc-smp | <2.6.38-13.52 | 2.6.38-13.52 |
=11.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)