USN-1534-1: Linux kernel (EC2) vulnerabilities
An error was discovered in the Linux kernel's network TUN/TAP device implementation. A local user with access to the TUN/TAP interface (which is not available to unprivileged users until granted by a root user) could exploit this flaw to crash the system or potential gain administrative privileges. (CVE-2012-2136) An error was discovered in the Linux kernel's memory subsystem (hugetlb). An unprivileged local user could exploit this flaw to cause a denial of service (crash the system). (CVE-2012-2390)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1534-1?
USN-1534-1 is classified as a high severity vulnerability due to the potential for local users to crash the system or gain administrative access.
How do I fix USN-1534-1?
To fix USN-1534-1, update the Linux kernel to version 2.6.32-347.52 or later on affected Ubuntu systems.
Who is affected by USN-1534-1?
Users running Ubuntu 10.04 with the specific Linux kernel version 2.6.32-347-ec2 may be affected by USN-1534-1.
Can USN-1534-1 be exploited remotely?
No, USN-1534-1 requires local access to the TUN/TAP interface, making it an exploit limited to users with local privileges.
What should I do if I am unable to update for USN-1534-1?
If you're unable to update for USN-1534-1, limit access to the TUN/TAP interface and monitor your system closely for unauthorized access.