USN-1452-1: Linux kernel vulnerabilities
A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. (CVE-2012-1601) Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. (CVE-2012-2123) A flaw was found in how the Linux kernel passed the replacement session keyring to a child process. An unprivileged local user could exploit this flaw to cause a denial of service (panic). (CVE-2012-2745)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1452-1?
USN-1452-1 is classified as a denial of service vulnerability.
How do I fix USN-1452-1?
You can resolve USN-1452-1 by upgrading to the kernel version 3.0.0-20.34.
Which Ubuntu versions are affected by USN-1452-1?
The affected version is Ubuntu 11.10.
What kind of users can exploit USN-1452-1?
An unprivileged local user can exploit USN-1452-1.
What component of the Linux kernel is involved in USN-1452-1?
USN-1452-1 involves a flaw in the Kernel Virtual Machine (KVM) virtual CPU setup.