USN-1457-1: Linux kernel vulnerabilities
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation. A remote NFS server (attacker) could exploit this flaw to cause a denial of service. (CVE-2011-4131) A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. (CVE-2012-1601) A flaw was discovered in the Linux kernel's KVM (kernel virtual machine). An administrative user in the guest OS could leverage this flaw to cause a denial of service in the host OS. (CVE-2012-2121) Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. (CVE-2012-2123) Schacher Raindel discovered a flaw in the Linux kernel's memory handling when hugetlb is enabled. An unprivileged local attacker could exploit this flaw to cause a denial of service and potentially gain higher privileges. (CVE-2012-2133)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-1457-1?
USN-1457-1 addresses vulnerabilities that could lead to denial of service attacks in the Linux kernel.
How do I fix USN-1457-1?
To fix USN-1457-1, upgrade your Linux kernel to version 2.6.38-15.60 or later as recommended in the advisory.
Which systems are affected by USN-1457-1?
USN-1457-1 affects Ubuntu 11.04 users running specific Linux kernel packages.
What symptoms might indicate an exploit of USN-1457-1?
Symptoms of an exploit of USN-1457-1 may include system crashes or unresponsive behavior due to denial of service.
Who discovered the issues addressed by USN-1457-1?
The vulnerabilities addressed by USN-1457-1 were discovered by Andy Adamson.