USN-1594-1: Linux kernel (Oneiric backport) vulnerabilities
Vadim Ponomarev discovered a flaw in the Linux kernel causing a reference leak when PID namespaces are used. A remote attacker could exploit this flaw causing a denial of service. (CVE-2012-2127) A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem handled MSI (Message Signaled Interrupts). A local unprivileged user could exploit this flaw to cause a denial of service or potentially elevate privileges. (CVE-2012-2137) Mathias Krause discover an error in Linux kernel's Datagram Congestion Control Protocol (DCCP) Congestion Control Identifier (CCID) use. A local attack could exploit this flaw to cause a denial of service (crash) and potentially escalate privileges if the user can mmap page 0. (CVE-2013-1827)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1594-1?
The severity of USN-1594-1 is classified as moderate due to the denial of service vulnerability.
How do I fix USN-1594-1?
You can fix USN-1594-1 by upgrading the Linux kernel to the patched version 3.0.0-26.43~lucid1 or later.
Which versions of Ubuntu are affected by USN-1594-1?
Ubuntu 10.04 is the affected version for the vulnerabilities addressed in USN-1594-1.
What kind of attack can exploit USN-1594-1?
A remote attacker could exploit the vulnerability in USN-1594-1 to cause a denial of service.
Is there a workaround for USN-1594-1?
There are no known workarounds for USN-1594-1; the recommended action is to apply the kernel update.