USN-1678-1: Linux kernel (Oneiric backport) vulnerability
Published Dec 20, 2012
·Updated
A flaw was discovered in the Linux kernel's handling of new hot-plugged memory. An unprivileged local user could exploit this flaw to cause a denial of service by crashing the system.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/linux-image-3.0.0-29-generic-pae<3.0.0-29.46~lucid1
3.0.0-29.46~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-29-virtual<3.0.0-29.46~lucid1
3.0.0-29.46~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-29-generic<3.0.0-29.46~lucid1
3.0.0-29.46~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-29-server<3.0.0-29.46~lucid1
3.0.0-29.46~lucid1
Ubuntu Ubuntu=10.04
Event History
Dec 20, 2012
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-1678-1?
The severity of USN-1678-1 is considered medium due to the potential for denial of service by an unprivileged local user.
2
How do I fix USN-1678-1?
To fix USN-1678-1, upgrade to the patched version linux-image-3.0.0-29.46~lucid1 or later on Ubuntu 10.04.
3
Who is affected by USN-1678-1?
USN-1678-1 affects Ubuntu 10.04 users running specific versions of the Linux kernel.
4
What causes the vulnerability in USN-1678-1?
The vulnerability in USN-1678-1 is caused by improper handling of new hot-plugged memory in the Linux kernel.
5
Can USN-1678-1 be exploited remotely?
No, USN-1678-1 can only be exploited locally by an unprivileged user on the affected system.