USN-1294-1: Linux kernel (Oneiric backport) vulnerabilities

Published Dec 8, 2011
·
Updated

Peter Huewe discovered an information leak in the handling of reading security-related TPM data. A local, unprivileged user could read the results of a previous TPM command. (CVE-2011-1162) Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy. (CVE-2011-2494) Qianfeng Zhang discovered that the bridge networking interface incorrectly handled certain network packets. A remote attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-2942) Yasuaki Ishimatsu discovered a flaw in the kernel's clock implementation. A local unprivileged attacker could exploit this causing a denial of service. (CVE-2011-3209) Zheng Liu discovered a flaw in how the ext4 filesystem splits extents. A local unprivileged attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-3638) Scot Doyle discovered that the bridge networking interface incorrectly handled certain network packets. A remote attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-4087) A bug was found in the way headroom check was performed in udp6ufofragment() function. A remote attacker could use this flaw to crash the system. (CVE-2011-4326)

Affected Software

8 affected componentsFixes available
All of the following
ubuntu/linux-image-3.0.0-13-virtual<3.0.0-13.22~lucid1
3.0.0-13.22~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-13-generic-pae<3.0.0-13.22~lucid1
3.0.0-13.22~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-13-server<3.0.0-13.22~lucid1
3.0.0-13.22~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-13-generic<3.0.0-13.22~lucid1
3.0.0-13.22~lucid1
Ubuntu Ubuntu=10.04

Event History

Dec 8, 2011
Advisory Published
via Ubuntu·12:00 AM

Frequently Asked Questions

1

What is the severity of USN-1294-1?

USN-1294-1 is classified as a high severity vulnerability due to the potential for local users to access sensitive information.

2

How do I fix USN-1294-1?

To fix USN-1294-1, upgrade to the updated Ubuntu package version 3.0.0-13.22~lucid1 for your specific kernel.

3

What types of systems are affected by USN-1294-1?

USN-1294-1 affects Ubuntu version 10.04 systems using the specified kernel packages.

4

Can a remote attacker exploit USN-1294-1?

No, USN-1294-1 is only exploitable by local, unprivileged users on the system.

5

What kind of data is leaked due to USN-1294-1?

USN-1294-1 allows local users to read results of previous TPM commands, potentially leaking sensitive security-related data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203