USN-1563-1: Linux kernel (Oneiric backport) vulnerability

Published Sep 10, 2012
·
Updated

A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation. A local, unprivileged user could use this flaw to cause a denial of service. (CVE-2012-2372) Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP device driver. A local user could exploit this flaw to examine part of the kernel's stack memory. (CVE-2012-6547) A flaw was found in Linux kernel's validation of CIPSO (Common IP Security Option) options set from userspace. A local user that can set a socket's CIPSO options could exploit this flaw to cause a denial of service (crash the system). (CVE-2013-0310)

Affected Software

8 affected componentsFixes available
All of the following
ubuntu/linux-image-3.0.0-25-generic<3.0.0-25.41~lucid1
3.0.0-25.41~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-25-server<3.0.0-25.41~lucid1
3.0.0-25.41~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-25-generic-pae<3.0.0-25.41~lucid1
3.0.0-25.41~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-25-virtual<3.0.0-25.41~lucid1
3.0.0-25.41~lucid1
Ubuntu Ubuntu=10.04

Event History

Sep 10, 2012
Advisory Published
via Ubuntu·12:00 AM

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

What is the severity of USN-1563-1?

The severity of USN-1563-1 is classified as a denial of service vulnerability affecting local, unprivileged users.

2

How do I fix USN-1563-1?

To fix USN-1563-1, update to the recommended version of the affected Linux kernel packages for Ubuntu 10.04.

3

What systems are affected by USN-1563-1?

USN-1563-1 affects Ubuntu 10.04 systems running specific versions of Linux kernel packages.

4

What specific vulnerabilities are reported in USN-1563-1?

USN-1563-1 reports on CVE-2012-2372 as an information leak and denial of service vulnerability in the Linux kernel.

5

Who discovered the vulnerabilities in USN-1563-1?

The vulnerabilities in USN-1563-1 were discovered by Mathias Krause.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203