USN-1489-1: Linux kernel (Oneiric backport) vulnerability
Published Jun 29, 2012
·Updated
A flaw was discovered in the Linux kernel's NFSv4 (Network file system) handling of ACLs (access control lists). A remote NFS server (attacker) could cause a denial of service (OOPS).
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/linux-image-3.0.0-22-virtual<3.0.0-22.36~lucid1
3.0.0-22.36~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-22-generic-pae<3.0.0-22.36~lucid1
3.0.0-22.36~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-22-server<3.0.0-22.36~lucid1
3.0.0-22.36~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-22-generic<3.0.0-22.36~lucid1
3.0.0-22.36~lucid1
Ubuntu Ubuntu=10.04
Event History
Jun 29, 2012
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-1489-1?
The severity of USN-1489-1 is considered high due to the potential for denial of service attacks.
2
How do I fix USN-1489-1?
To fix USN-1489-1, you should upgrade to the linux-image package version 3.0.0-22.36~lucid1 or later.
3
Which systems are affected by USN-1489-1?
USN-1489-1 affects Ubuntu 10.04 systems running the specified versions of the linux-image packages.
4
What is the nature of the vulnerability in USN-1489-1?
The vulnerability identified in USN-1489-1 involves a flaw in the Linux kernel's handling of ACLs in NFSv4, which can lead to a denial of service.
5
Can USN-1489-1 be exploited remotely?
Yes, USN-1489-1 can be exploited remotely by an attacker using a malicious NFS server.