USN-1405-1: Linux kernel vulnerabilities
Paolo Bonzini discovered a flaw in Linux's handling of the SGIO ioctl command. A local user, or user in a VM could exploit this flaw to bypass restrictions and gain read/write access to all data on the affected block device. (CVE-2011-4127) A flaw was found in the Linux kernel's ext4 file system when mounting a corrupt filesystem. A user-assisted remote attacker could exploit this flaw to cause a denial of service. (CVE-2012-2100)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1405-1?
The severity of USN-1405-1 is considered high due to the potential for local users to gain unauthorized access to block device data.
How do I fix USN-1405-1?
To fix USN-1405-1, users should update to the kernel version 3.0.0-16.29 or later.
What systems are affected by USN-1405-1?
USN-1405-1 affects Ubuntu 11.10 systems running specific versions of the Linux kernel.
Who discovered the vulnerability leading to USN-1405-1?
The vulnerability leading to USN-1405-1 was discovered by Paolo Bonzini.
What kind of access can an attacker gain through USN-1405-1?
An attacker exploiting USN-1405-1 can bypass restrictions to gain read/write access to all data on the affected block device.