USN-1738-1: Linux kernel (Oneiric backport) vulnerability
Published Feb 22, 2013
·Updated
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered a race condition in the Linux kernel's ptrace syscall. An unprivileged local attacker could exploit this flaw to run programs as an administrator.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/linux-image-3.0.0-31-server<3.0.0-31.49~lucid1
3.0.0-31.49~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-31-generic<3.0.0-31.49~lucid1
3.0.0-31.49~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-31-virtual<3.0.0-31.49~lucid1
3.0.0-31.49~lucid1
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-3.0.0-31-generic-pae<3.0.0-31.49~lucid1
3.0.0-31.49~lucid1
Ubuntu Ubuntu=10.04
Event History
Feb 22, 2013
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-1738-1?
The severity of USN-1738-1 is critical due to its potential for local privilege escalation.
2
How can USN-1738-1 be exploited?
USN-1738-1 can be exploited by an unprivileged local attacker who uses the ptrace syscall to execute programs with elevated privileges.
3
What versions of Ubuntu are affected by USN-1738-1?
USN-1738-1 affects Ubuntu 10.04 with specific versions of the linux-image packages.
4
How do I fix USN-1738-1?
To fix USN-1738-1, upgrade to linux-image-3.0.0-31.49~lucid1 or higher.
5
Who discovered the vulnerability in USN-1738-1?
The vulnerability in USN-1738-1 was discovered by Suleiman Souhlal, Salman Qazi, Aaron Durbin, and Michael Davidson.